Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 6Objective 2

Analysis of Competing Hypotheses TIE Practice Questions (Page 7)

Part of the Threat Intelligence Analysis domain, which makes up ~14% of our current practice bank.

45questions here
9free pages
10concepts

Questions 31–35

  1. 31foundation · easy

    In an ACH report, how should the likelihood of each hypothesis be communicated?

    Select an answer first
  2. 32application · medium

    Your team is new to ACH and is about to start their first analysis. They have already identified the hypotheses and listed the evidence. According to the ACH process, what is the next step they should perform?

    Select an answer first
  3. 33application · medium

    An analyst is using ACH to determine whether a recent data exfiltration was caused by an external attacker, a malicious insider, or an accidental leak. The ACH matrix shows that the external attacker hypothesis is slightly more consistent with the evidence than the other two. However, the analyst notices that the evidence 'unusual outbound network traffic' is marked as consistent with both the external attacker and the accidental leak hypotheses, but the interpretation of that evidence depends on whether the traffic was encrypted or not. What should the analyst do to improve the reliability of the analysis?

    Select an answer first
  4. 34foundation · easy

    In an ACH matrix, what does a '+' (plus) sign typically indicate?

    Select an answer first
  5. 35foundation · easy

    In ACH, what does it mean for evidence to have high 'diagnosticity'?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.