Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 5Objective 2

Aggregation, Analysis, and Dissemination Within TIPs TIE Practice Questions (Page 6)

Part of the Threat Intelligence Platforms domain, which makes up ~13% of our current practice bank.

40questions here
8free pages
4concepts

Questions 26–30

  1. 26application · medium

    A security operations team uses a TIP to ingest threat feeds from multiple commercial vendors, open-source lists, and internal firewall logs. Analysts complain that the same indicator appears with different formats (e.g., '1.2.3.4' vs '1.2.3.4/32') and different confidence scores depending on the source. They want a single, deduplicated view with a unified confidence score. What should the TIP administrator configure to address this?

    Select an answer first
  2. 27application · medium

    A security operations center uses a TIP to manage threat intelligence. The SOC manager wants to ensure that when a new high-severity indicator is added to the TIP, the on-call analyst is immediately notified via a mobile alert, and the indicator is automatically added to the SIEM's watchlist. The TIP supports webhooks and SIEM integration. What should the SOC manager configure?

    Select an answer first
  3. 28expert · hard

    A TIP administrator is integrating a new open-source threat feed that provides indicators in CSV format with columns: 'ip', 'domain', 'hash', 'first_seen', 'last_seen', and 'tags'. The TIP's native schema requires indicators to have a type (IP, domain, hash) and a confidence score. The feed does not provide confidence scores. The administrator wants to use this feed for both automated blocking and analyst research. What is the best approach?

    Select an answer first
  4. 29application · medium

    A TIP is configured to automatically push indicators to a firewall and a SIEM. The firewall is down for maintenance, and the SIEM is receiving the indicators. The TIP administrator wants to ensure that the firewall receives the indicators once it is back online. What should the administrator do?

    Select an answer first
  5. 30application · medium

    An analyst is investigating a suspicious domain that was flagged by a threat feed. The analyst wants to know if the domain is associated with any known malware families, who registered it, and whether it has been seen in any internal network traffic. What should the analyst do within the TIP?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.