
EC-CouncilThreat Intelligence Essentials
Domain 6Objective 1
Data Analysis Techniques TIE Practice Questions (Page 12)
Part of the Threat Intelligence Analysis domain, which makes up ~14% of our current practice bank.
59questions here
12free pages
12concepts
Questions 56–59
- 56
A security analyst is reviewing a year of authentication logs and notices that the number of failed logon attempts per day has been steadily increasing. The analyst wants to determine whether the increase is a gradual trend or an anomaly that requires immediate investigation. Which statistical method is most appropriate for this analysis?
Select an answer first - 57
A security operations center observes that the number of phishing emails targeting the finance department has increased by 40% over the last month, while other departments have seen no change. To determine whether this is a significant shift or just random variation, which statistical method is most appropriate?
Select an answer first - 58
What is the primary purpose of data normalization in threat intelligence analysis?
Select an answer first - 59
An analyst has an IP address from a security alert. Which of the following actions would be considered data enrichment?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to TIE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.