
EC-CouncilThreat Intelligence Essentials
Domain 6Objective 1
Data Analysis Techniques TIE Practice Questions (Page 10)
Part of the Threat Intelligence Analysis domain, which makes up ~14% of our current practice bank.
59questions here
12free pages
12concepts
Questions 46–50
- 46
Which type of machine learning is commonly used to detect anomalies in network traffic?
Select an answer first - 47
A threat intelligence analyst has extracted a list of suspicious IP addresses from internal DNS logs. The analyst wants to determine which of these IPs are known command-and-control (C2) servers and what malware families they are associated with. Which approach best improves the value of this raw data?
Select an answer first - 48
During an incident response, an analyst observes that the attacker used a spear-phishing email with a malicious attachment, then used PowerShell to download a payload, and finally established persistence via a scheduled task. What is the most valuable output for the organization's defensive team?
Select an answer first - 49
Which of the following is a common standard used to normalize threat intelligence data?
Select an answer first - 50
A threat intelligence team has identified two active threats: Threat A has a high likelihood of occurring but low impact, while Threat B has a low likelihood but high impact. The team has limited resources to address only one threat. Which threat should be prioritized?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.