
EC-CouncilThreat Intelligence Essentials
Domain 3Objective 3
Advanced Persistent Threats (APTs) TIE Practice Questions (Page 7)
Part of the Cyber Threat Landscape domain, which makes up ~11% of our current practice bank.
42questions here
9free pages
6concepts
Questions 31–35
- 31
A security analyst is studying the 2016 Democratic National Committee (DNC) breach, which involved spear-phishing and custom malware attributed to a Russian state-sponsored group. The analyst wants to identify a key lesson from this case study that applies to defending against similar APT attacks. Which lesson is most directly applicable?
Select an answer first - 32
Which stage of the APT attack chain involves the attacker identifying potential entry points and vulnerabilities in the target environment?
Select an answer first - 33
A threat hunter is analyzing a network where an APT has established a foothold. The hunter has limited resources and must choose where to focus detection efforts. The hunter has observed: (1) the attacker is using a previously unknown malware variant, (2) the malware communicates with a C2 server using HTTP on a non-standard port, and (3) the attacker is using stolen credentials to access multiple systems. Which detection approach is most likely to yield the earliest warning of the attacker's activities?
Select an answer first - 34
Which of the following is a common indicator of compromise (IoC) associated with APT activity?
Select an answer first - 35
A SOC analyst is reviewing a report that lists several indicators of compromise (IoCs) for a known APT group. The report includes a file hash, a domain name, and an IP address. The analyst wants to search their environment for these IoCs. Which tool or technique would be most effective for searching for all three types of IoCs?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.