Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 5Objective 3

Automation and Orchestration of Threat Intelligence TIE Practice Questions (Page 2)

Part of the Threat Intelligence Platforms domain, which makes up ~13% of our current practice bank.

56questions here
12free pages
11concepts

Questions 6–10

  1. 6expert · hard

    A large enterprise has a SOAR platform and a TIP. They want to automate the response to phishing emails: extract indicators, enrich them, and if the indicators are malicious, block the sender and quarantine the email. The team is debating whether to implement this as a single automation rule or as an orchestrated playbook. What is the key advantage of using an orchestrated playbook over a single automation rule?

    Select an answer first
  2. 7expert · hard

    An organization has a TIP that identifies malicious domains. They want to automatically block these domains on their DNS server and also notify the security team. The DNS server has an API, and the TIP supports webhooks. What is the most reliable way to implement this integration?

    Select an answer first
  3. 8application · medium

    A playbook is designed to automatically quarantine a workstation when a high-confidence malware alert is received from the EDR. The team is concerned about false positives that could lock out legitimate users. What should the playbook include to reduce this risk?

    Select an answer first
  4. 9application · medium

    During an active incident, a security analyst needs to quickly gather evidence from multiple sources: the SIEM, the EDR, and the firewall logs. The analyst also needs to isolate the affected host. The organization has a SOAR platform integrated with these tools. What is the most efficient way to perform these actions?

    Select an answer first
  5. 10application · medium

    During an active incident, a SOAR playbook automatically collects memory dumps from affected endpoints and then isolates those endpoints from the network. The playbook is triggered by a high-severity alert from the SIEM. What is the primary benefit of this orchestration?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.