Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 5Objective 3

Automation and Orchestration of Threat Intelligence TIE Practice Questions (Page 9)

Part of the Threat Intelligence Platforms domain, which makes up ~13% of our current practice bank.

56questions here
12free pages
11concepts

Questions 41–45

  1. 41application · medium

    A TIP administrator is designing a playbook to automate alert triage. The playbook should enrich each alert's IP address with geolocation and reputation data, then assign a priority based on the reputation score. The team wants to avoid unnecessary enrichment calls for internal IP addresses. What is the most appropriate first step in the playbook?

    Select an answer first
  2. 42application · medium

    An organization receives a high volume of alerts for potentially malicious domains. The security team wants to automate the triage process: for each alert, the TIP should query an external threat intelligence feed for reputation data, and if the reputation score is above a threshold, the alert should be escalated to a human analyst. If the score is below the threshold, the alert should be closed automatically. What is the best way to design this playbook?

    Select an answer first
  3. 43expert · hard

    A security team is automating the enrichment of indicators using multiple external threat intelligence feeds. They notice that some feeds are slow to respond, causing the enrichment workflow to time out. They want to ensure that enrichment completes within a reasonable time and does not block other workflows. What is the best practice to address this?

    Select an answer first
  4. 44application · medium

    A company uses a TIP to manage indicators of compromise (IOCs). They want to automatically revoke indicators that have not been seen in the wild for 90 days and remove them from the firewall block list. What is the best way to implement this?

    Select an answer first
  5. 45application · medium

    An organization's TIP automatically enriches every IP address with three external threat feeds. Analysts are overwhelmed by alerts because many IPs are flagged by only one feed with low confidence. The team wants to reduce false positives while still enriching all IPs. What is the best approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.