Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 6Objective 2

Analysis of Competing Hypotheses TIE Practice Questions (Page 1)

Part of the Threat Intelligence Analysis domain, which makes up ~14% of our current practice bank.

45questions here
9free pages
10concepts

Questions 1–5

  1. 1expert · hard

    An analyst is conducting an ACH analysis on a series of data exfiltration events. The analyst has generated four hypotheses and is now collecting evidence. However, the analyst has a strong personal belief that the exfiltration is the work of a specific APT group. This belief influences which evidence the analyst considers relevant and how it is interpreted. What is the most effective way to mitigate this bias?

    Select an answer first
  2. 2application · medium

    You are leading an ACH session for a new threat campaign. The team has just generated a list of hypotheses and is about to evaluate evidence. According to the ACH process, what should happen immediately after the hypotheses are identified?

    Select an answer first
  3. 3expert · hard

    Your ACH matrix ranks Hypothesis A as most likely, but you are concerned because the ranking depends heavily on the assumption that the 'attacker's IP address is not a proxy' is reliable. You have doubts about this assumption. What is the best way to handle this uncertainty in your analysis?

    Select an answer first
  4. 4application · medium

    An analyst is building an ACH matrix and includes only evidence that supports the hypothesis they believe is correct, while excluding evidence that contradicts it. Which ACH pitfall is this analyst committing?

    Select an answer first
  5. 5application · medium

    A threat intelligence analyst is investigating a series of spear-phishing emails targeting the finance department. The emails use a recently discovered malware family and the sender addresses mimic the CEO's name. The analyst has three hypotheses: (A) a financially motivated cybercriminal group, (B) an insider with access to internal email templates, and (C) a nation-state actor conducting reconnaissance. When building an ACH matrix, the analyst marks the evidence 'malware family used' as consistent with hypothesis A and C, but inconsistent with B. What is the most appropriate next step in the ACH process?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.