
EC-CouncilThreat Intelligence Essentials
Domain 5Objective 3
Automation and Orchestration of Threat Intelligence TIE Practice Questions (Page 5)
Part of the Threat Intelligence Platforms domain, which makes up ~13% of our current practice bank.
56questions here
12free pages
11concepts
Questions 21–25
- 21
What is the purpose of automating the expiration of indicators in a Threat Intelligence Platform?
Select an answer first - 22
What is a common challenge when implementing automation and orchestration in threat intelligence?
Select an answer first - 23
A company wants to automatically block malicious IP addresses on their perimeter firewall as soon as they are identified by their TIP. The TIP has an API, and the firewall vendor provides an API for updating block lists. What is the most appropriate integration approach?
Select an answer first - 24
Which of the following is a key automation capability commonly found in a Threat Intelligence Platform (TIP)?
Select an answer first - 25
An organization's TIP automatically shares indicators with a partner organization via a trusted feed. Some indicators are sensitive and should not be shared. The team wants to automate sharing while ensuring sensitive indicators are excluded. What is the best approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.