
EC-CouncilThreat Intelligence Essentials
Domain 3Objective 3
Advanced Persistent Threats (APTs) TIE Practice Questions (Page 3)
Part of the Cyber Threat Landscape domain, which makes up ~11% of our current practice bank.
42questions here
9free pages
6concepts
Questions 11–15
- 11
A security analyst is reviewing a report that describes an attack where the threat actor used a previously unknown vulnerability in a web server, then installed a rootkit that hid their presence, and finally stole customer data over a period of several weeks. Which combination of APT characteristics is most clearly demonstrated?
Select an answer first - 12
A cybersecurity analyst at a government defense contractor is reviewing threat intelligence reports. One report describes a group that has repeatedly targeted aerospace and defense organizations, uses spear-phishing with zero-day exploits, and is believed to be state-sponsored with a focus on intellectual property theft. Another report describes a financially motivated group that uses ransomware against hospitals. Which threat actor profile is most consistent with the first report?
Select an answer first - 13
A threat intelligence analyst is compiling a report on APT groups that target the energy sector. The analyst has information about a group that has been active since 2015, uses custom malware, and has been linked to attacks on power grids in Eastern Europe. The group's motivation appears to be geopolitical disruption. Which classification best fits this group?
Select an answer first - 14
A security analyst is reviewing network logs and sees a series of DNS queries to a domain that is algorithmically generated (DGA). The analyst also notices that the queries occur at regular intervals and are made by a host that has been infected with a known APT malware. Which action would be most effective in disrupting the attacker's command and control (C2) communication?
Select an answer first - 15
A security team is analyzing the 2013 Target breach, where attackers gained access through a third-party HVAC vendor and then moved laterally to the point-of-sale (POS) system. The team wants to apply lessons from this case study to their own environment. Which combination of controls would be most effective in preventing a similar attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.