
EC-CouncilThreat Intelligence Essentials
Domain 5Objective 3
Automation and Orchestration of Threat Intelligence TIE Practice Questions (Page 6)
Part of the Threat Intelligence Platforms domain, which makes up ~13% of our current practice bank.
56questions here
12free pages
11concepts
Questions 26–30
- 26
What is the primary purpose of automated indicator sharing in a Threat Intelligence Platform?
Select an answer first - 27
What is the role of a 'condition' in an automated threat intelligence workflow?
Select an answer first - 28
A company's TIP detects a malicious domain and automatically sends a block command to the firewall. However, the domain is still resolving on some endpoints because the DNS server caches the record. What additional integration should the TIP use to ensure the domain is blocked effectively?
Select an answer first - 29
A security operations team wants to automate the initial triage of alerts from their SIEM. They want the TIP to enrich indicators, then automatically block malicious IPs on the firewall, and finally open an incident ticket. The team has a SOAR platform and a TIP that both support API integrations. What is the most effective way to implement this workflow?
Select an answer first - 30
How do orchestration tools typically integrate with a Threat Intelligence Platform (TIP)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.