Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 3Objective 3

Advanced Persistent Threats (APTs) TIE Practice Questions (Page 9)

Part of the Cyber Threat Landscape domain, which makes up ~11% of our current practice bank.

42questions here
9free pages
6concepts

Questions 41–42

  1. 41application · medium

    A security analyst notices a series of small, encrypted data transfers from a research lab's file server to an external IP address during off-hours. The transfers occur every few days and are just under the threshold that triggers the existing data-loss prevention alerts. The analyst also finds a scheduled task on the server that runs a PowerShell script to compress and encrypt files in a specific folder before the transfers. Which stage of the APT lifecycle does this activity most directly represent?

    Select an answer first
  2. 42application · medium

    A threat hunter is reviewing logs from a company that discovered a breach. The timeline shows: (1) an employee received a spear-phishing email with a malicious attachment, (2) the attachment installed a backdoor, (3) the backdoor established outbound connections to a command-and-control server, (4) the attacker used stolen credentials to move laterally to a database server, and (5) the attacker compressed and encrypted files before transferring them out. The hunter wants to map these events to the APT lifecycle to prioritize detection controls. Which stage of the APT lifecycle is most directly associated with the attacker's use of stolen credentials to access the database server?

    Select an answer first
Finished these 2 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to TIE

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.