
EC-CouncilThreat Intelligence Essentials
Domain 6Objective 1
Data Analysis Techniques TIE Practice Questions (Page 1)
Part of the Threat Intelligence Analysis domain, which makes up ~14% of our current practice bank.
59questions here
12free pages
12concepts
Questions 1–5
- 1
An analyst notices that a specific IP address appears in firewall logs, and the same IP is also found in a threat intelligence feed as a command-and-control server. What technique is the analyst applying?
Select an answer first - 2
A threat intelligence analyst needs to collect data from a variety of sources. Which of the following is an example of an internal source of threat intelligence data?
Select an answer first - 3
An analyst has correlated multiple data sources and identified a complex attack pattern involving lateral movement across several hosts. The analyst needs to present this pattern to both technical and non-technical audiences. Which visualization approach is most effective?
Select an answer first - 4
A security analyst at a mid-sized firm discovers a suspicious file hash in an internal sandbox report. The hash is not found in the firm's internal threat feed. To quickly determine whether this hash is associated with a known campaign, which action is most appropriate?
Select an answer first - 5
A financial institution is planning to deploy a new online banking application. The security team wants to systematically identify potential threats and vulnerabilities in the application before it goes live. Which approach should they use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.