
EC-CouncilThreat Intelligence Essentials
Domain 5Objective 2
Aggregation, Analysis, and Dissemination Within TIPs TIE Practice Questions (Page 4)
Part of the Threat Intelligence Platforms domain, which makes up ~13% of our current practice bank.
40questions here
8free pages
4concepts
Questions 16–20
- 16
A TIP is integrated with a SIEM and an EDR. The SIEM receives indicators and creates detection rules, but the EDR does not have an integration with the TIP. The security team wants the EDR to also block malicious files based on TIP indicators. What should the administrator do?
Select an answer first - 17
A TIP is integrated with a SIEM. The SIEM team wants to receive real-time alerts when new high-confidence indicators are added to the TIP. What should the TIP administrator configure?
Select an answer first - 18
A company's TIP is integrated with its SIEM and endpoint detection and response (EDR) platform. The security team wants to automatically block malicious indicators on endpoints, but they are concerned about false positives disrupting business operations. The TIP allows setting confidence thresholds for automated actions. What is the best configuration?
Select an answer first - 19
A security operations center (SOC) ingests threat data from a commercial feed, an open-source feed, and internal firewall logs into its threat intelligence platform. Analysts complain that the same indicator appears multiple times with different formats (e.g., IP addresses with and without leading zeros, domain names in uppercase and lowercase). The SOC manager wants to ensure that when an analyst searches for an indicator, all related observations appear in a single result. What should the SOC manager configure in the TIP?
Select an answer first - 20
A threat intelligence team has finished analyzing a new malware campaign and needs to ensure that the SOC analysts receive the indicators in their SIEM, the incident response team gets a detailed report, and the executive team receives a high-level summary. The TIP supports integrations with SIEM, email, and ticketing systems. What is the most efficient way to achieve this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.