
EC-CouncilThreat Intelligence Essentials
Domain 5Objective 2
Aggregation, Analysis, and Dissemination Within TIPs TIE Practice Questions (Page 5)
Part of the Threat Intelligence Platforms domain, which makes up ~13% of our current practice bank.
40questions here
8free pages
4concepts
Questions 21–25
- 21
A company's TIP is integrated with its SIEM and ticketing system. When the TIP identifies a new malicious domain, the SIEM should automatically create a ticket for the incident response team. However, the tickets are not being created. The TIP's integration logs show that the SIEM received the indicator successfully. What is the most likely issue?
Select an answer first - 22
A TIP administrator is configuring a new threat feed that provides indicators in STIX 2.1 format. The TIP's native schema uses an older custom format that lacks several STIX fields, such as 'kill chain phases' and 'granular markings'. The administrator wants to preserve as much context as possible for downstream analysis. What should the administrator do?
Select an answer first - 23
Which of the following best describes the dissemination function in a threat intelligence platform?
Select an answer first - 24
In a threat intelligence platform, what is the primary purpose of correlation during the analysis phase?
Select an answer first - 25
How does a TIP typically support the aggregation process through workflow integration with external threat intelligence feeds?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.