Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 2Objective 4

Augmenting Vulnerability Management with Threat Intelligence TIE Practice Questions (Page 9)

Part of the Types of Threat Intelligence domain, which makes up ~11% of our current practice bank.

46questions here
10free pages
6concepts

Questions 41–45

  1. 41application · medium

    A security manager wants to justify the investment in threat intelligence to the board. The team has been using threat intelligence to prioritize vulnerabilities for six months. Which KPI would most convincingly demonstrate the value of threat intelligence in vulnerability management?

    Select an answer first
  2. 42foundation · easy

    What is a common benefit of orchestrating vulnerability management with threat intelligence?

    Select an answer first
  3. 43application · medium

    During a vulnerability assessment, a security analyst finds a vulnerability in a web application that is not currently being exploited. However, threat intelligence reports indicate that a known advanced persistent threat (APT) group has recently developed a weaponized exploit for this vulnerability and is targeting organizations in the same industry. What should the analyst do?

    Select an answer first
  4. 44application · medium

    A vulnerability management team is deciding which vulnerabilities to remediate in the next patch cycle. They have two vulnerabilities: one with a CVSS score of 9.8 that is not being exploited and affects an internal development server, and another with a CVSS score of 7.2 that is being actively exploited in the wild and affects a public-facing web server. Which vulnerability should be remediated first?

    Select an answer first
  5. 45expert · hard

    A security team wants to automate vulnerability prioritization using threat intelligence, but they are concerned about the accuracy of the threat intelligence feeds and the potential for false positives. They also need to ensure that critical vulnerabilities are not missed. Which approach best balances automation with human oversight?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.