
EC-CouncilThreat Intelligence Essentials
Domain 2Objective 4
Augmenting Vulnerability Management with Threat Intelligence TIE Practice Questions (Page 6)
Part of the Types of Threat Intelligence domain, which makes up ~11% of our current practice bank.
46questions here
10free pages
6concepts
Questions 26–30
- 26
An organization uses a vulnerability management platform that supports API integrations. They want to automatically prioritize vulnerabilities based on threat intelligence and assign them to the appropriate remediation teams. Which automation strategy would be most effective?
Select an answer first - 27
A security team must prioritize vulnerabilities across two business units. Business unit A runs an internet-facing customer portal with a vulnerability that has a CVSS score of 6.5 and is listed in a public exploit database, but there is no evidence of active exploitation. Business unit B runs an internal HR system with a vulnerability that has a CVSS score of 9.0, but threat intelligence shows no known exploit and the system is not accessible from the internet. The team has limited patching capacity and must choose which to remediate first. Which decision best balances real-world risk and business impact?
Select an answer first - 28
In the vulnerability management lifecycle, what is the primary purpose of the prioritization stage?
Select an answer first - 29
A security analyst at a mid-sized company is reviewing a weekly vulnerability scan report. The report lists a critical-severity vulnerability in a legacy web server that has been present for six months. The analyst checks threat intelligence feeds and finds that the vulnerability is not being exploited in the wild, has no known exploit code, and is not mentioned in any current threat actor campaigns. However, the vulnerability is rated CVSS 9.8. According to threat-intelligence-informed prioritization, what should the analyst do with this vulnerability?
Select an answer first - 30
A security team wants to automate the response to vulnerabilities that are actively exploited in their industry. They have a SOAR platform and access to sector-specific threat intelligence. Which automation workflow would best leverage this intelligence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.