
EC-CouncilThreat Intelligence Essentials
Domain 5Objective 3
Automation and Orchestration of Threat Intelligence TIE Practice Questions (Page 8)
Part of the Threat Intelligence Platforms domain, which makes up ~13% of our current practice bank.
56questions here
12free pages
11concepts
Questions 36–40
- 36
A security analyst at a mid-sized company manually reviews every phishing alert from the email gateway. The analyst wants to reduce this workload by having the TIP automatically enrich each reported URL with reputation data, and then, only if the URL is confirmed malicious, automatically create a ticket in the ticketing system. The analyst does not want any other automated actions to occur. What should the analyst configure?
Select an answer first - 37
Which of the following is an example of an automated containment action in incident response?
Select an answer first - 38
A security team wants to measure the effectiveness of their SOAR playbooks. They have data on playbook execution times, false positive rates, and the number of incidents escalated to human analysts. What is the most meaningful metric to track for continuous improvement?
Select an answer first - 39
What is the primary goal of automating data enrichment in threat intelligence?
Select an answer first - 40
Which scenario best illustrates orchestration rather than simple automation in a threat intelligence context?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.