Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 3Objective 3

Advanced Persistent Threats (APTs) TIE Practice Questions (Page 2)

Part of the Cyber Threat Landscape domain, which makes up ~11% of our current practice bank.

42questions here
9free pages
6concepts

Questions 6–10

  1. 6application · medium

    A threat intelligence analyst is reviewing logs and notices that a workstation in the finance department is making DNS queries to a domain that was registered only three days ago and has a very low reputation score. The workstation also established a persistent connection to an IP address in a country where the company has no business operations. Which two indicators of compromise (IoCs) are most directly highlighted by this observation?

    Select an answer first
  2. 7application · medium

    A security operations center (SOC) is investigating a potential APT. They notice a series of failed login attempts from a single IP address, followed by a successful login from the same IP using a legitimate account. The account then accessed a large number of files on a file share. Which detection strategy would be most effective in identifying this as malicious activity?

    Select an answer first
  3. 8application · medium

    A SOC analyst is reviewing a report from an EDR solution that flags a process running from a temporary directory with a known malicious file hash. The analyst also notices that the process is making HTTP requests to a domain that has been associated with a known APT group. Which two indicators of compromise (IoCs) are present in this scenario?

    Select an answer first
  4. 9application · medium

    A security analyst at a mid-sized manufacturing firm notices a series of small, encrypted data transfers from a single engineering workstation to an external IP address over the past three months. The transfers occur every few days, always at 2:00 AM, and the workstation shows no signs of malware in standard scans. The analyst also finds that the workstation has been sending beacon-like signals to a domain registered three years ago that has no web content. Which combination of observations most strongly indicates an APT rather than a typical malware infection?

    Select an answer first
  5. 10foundation · easy

    Which APT group is commonly associated with the Chinese government and has been observed targeting aerospace, technology, and government sectors for intellectual property theft?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.