
EC-CouncilThreat Intelligence Essentials
Domain 5Objective 2
Aggregation, Analysis, and Dissemination Within TIPs TIE Practice Questions (Page 7)
Part of the Threat Intelligence Platforms domain, which makes up ~13% of our current practice bank.
40questions here
8free pages
4concepts
Questions 31–35
- 31
A TIP analyst notices that a single IP address appears in a phishing campaign feed, a malware analysis report, and an internal intrusion detection alert. The analyst wants to determine if these are related to the same threat actor. What TIP analysis feature should the analyst use?
Select an answer first - 32
A company is deploying a TIP and wants to ensure that it can ingest data from a variety of sources, including email gateways, DNS logs, and threat feeds. The team is concerned about the volume of data and wants to ensure that the TIP can handle the load without performance degradation. What is the most important factor to consider?
Select an answer first - 33
An organization uses a TIP, a SIEM, and an EDR platform. The TIP receives indicators from external feeds and internal investigations. The security team wants the SIEM to automatically create detection rules based on new high-confidence indicators from the TIP. What should the administrator configure?
Select an answer first - 34
A threat intelligence team is required to share threat intelligence with external partners, such as industry peers and government agencies. The team must ensure that sensitive information, such as internal system names, is not disclosed. The TIP supports data marking and sharing groups. What is the best approach?
Select an answer first - 35
An organization's TIP is configured to ingest indicators from a SIEM, a threat feed, and a vulnerability scanner. The SIEM sends events in real time, the threat feed updates every hour, and the vulnerability scanner runs daily. The TIP is currently set to poll all sources every 24 hours. Analysts are missing timely indicators from the SIEM. What should the administrator do to improve timeliness without overloading the TIP?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.