Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 2Objective 4

Augmenting Vulnerability Management with Threat Intelligence TIE Practice Questions (Page 2)

Part of the Types of Threat Intelligence domain, which makes up ~11% of our current practice bank.

46questions here
10free pages
6concepts

Questions 6–10

  1. 6foundation · easy

    Which factor, when combined with CVSS scores, helps prioritize vulnerabilities based on real-world risk?

    Select an answer first
  2. 7application · medium

    A vulnerability management analyst is reviewing a critical vulnerability in a legacy application that is not exposed to the internet. The CVSS score is 9.8, but threat intelligence shows no known exploit code and no threat actor activity targeting this application. Meanwhile, a medium-severity vulnerability in an internet-facing web server has a public exploit and is being actively used in ransomware campaigns. How should the analyst contextualize these findings?

    Select an answer first
  3. 8application · medium

    A security team has integrated threat intelligence into their vulnerability management process. They want to track a KPI that demonstrates the value of this integration to management. Which KPI would be most meaningful?

    Select an answer first
  4. 9application · medium

    A vulnerability management team is establishing a formal lifecycle process. They have completed the identification and assessment stages and now need to decide how to prioritize remediation. They have access to threat intelligence that includes exploit kits, dark web discussions, and vendor advisories. Which action best incorporates threat intelligence into the prioritization stage?

    Select an answer first
  5. 10expert · hard

    A security team is overwhelmed by the number of vulnerabilities and needs to prioritize remediation. They have a vulnerability with a CVSS score of 9.0 that affects a critical internal database but is not being exploited and has no known exploit code. They also have a vulnerability with a CVSS score of 7.5 that affects an internet-facing web server and is listed in CISA's Known Exploited Vulnerabilities catalog. The team has limited resources and can only remediate one vulnerability this week. Which vulnerability should they remediate first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.