
EC-CouncilThreat Intelligence Essentials
Domain 6Objective 2
Analysis of Competing Hypotheses TIE Practice Questions (Page 2)
Part of the Threat Intelligence Analysis domain, which makes up ~14% of our current practice bank.
45questions here
9free pages
10concepts
Questions 6–10
- 6
An intelligence team is using ACH to analyze a series of ransomware attacks. The team has identified three hypotheses: a known ransomware group, a new group using leaked code, and an insider. During the analysis, the team discovers that the ransomware code contains a unique string that has only been seen in one previous attack attributed to a different group. What should the team do?
Select an answer first - 7
An analyst is applying ACH to determine whether a series of login anomalies are due to a credential-stuffing bot, a targeted attacker, or a misconfigured application. The analyst has collected evidence from logs and threat feeds. However, the analyst only included evidence that was easy to obtain and ignored logs that were difficult to parse. What is the primary pitfall this analyst is falling into?
Select an answer first - 8
What is a limitation of ACH that analysts should be aware of?
Select an answer first - 9
After building an ACH matrix, you notice that the top two hypotheses are nearly tied. The only evidence that separates them is a single report from an unverified source. What is the most appropriate next step?
Select an answer first - 10
In the eight-step ACH process, what is the first step an analyst should perform?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.