Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 5Objective 3

Automation and Orchestration of Threat Intelligence TIE Practice Questions (Page 4)

Part of the Threat Intelligence Platforms domain, which makes up ~13% of our current practice bank.

56questions here
12free pages
11concepts

Questions 16–20

  1. 16application · medium

    A TIP automatically blocks an IP address on the firewall for 24 hours after detection. After 24 hours, the block expires, but the TIP still shows the indicator as active. The security team wants the indicator to be automatically revoked from the firewall and marked as expired in the TIP when the block expires. What should be configured?

    Select an answer first
  2. 17application · medium

    A TIP administrator wants to automate the process of ingesting indicators from a new OSINT feed, enriching them with internal asset data, and then publishing them to the organization's firewall blocklist. The TIP supports API-based integrations. What is the most efficient way to set this up?

    Select an answer first
  3. 18foundation · easy

    In a threat intelligence workflow, what is the primary difference between automation and orchestration?

    Select an answer first
  4. 19foundation · easy

    Which of the following is an example of an external source used for automated indicator enrichment?

    Select an answer first
  5. 20foundation · easy

    How does a Threat Intelligence Platform (TIP) typically integrate with a SIEM to enable automated response?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.