
EC-CouncilThreat Intelligence Essentials
Domain 6Objective 1
Data Analysis Techniques TIE Practice Questions (Page 7)
Part of the Threat Intelligence Analysis domain, which makes up ~14% of our current practice bank.
59questions here
12free pages
12concepts
Questions 31–35
- 31
A security operations center (SOC) analyst is correlating firewall logs with endpoint detection alerts. The firewall logs use IP addresses and port numbers, while the endpoint alerts use hostnames and process names. The analyst needs to identify whether a specific external IP address is associated with a series of failed logon attempts on multiple hosts. Which action should the analyst take first to enable effective correlation?
Select an answer first - 32
A threat intelligence analyst has completed an analysis of a new malware campaign targeting the organization. The analyst needs to inform the executive leadership about the potential business impact and the board of directors about the strategic implications. What is the most effective way to disseminate this intelligence?
Select an answer first - 33
A security operations center is correlating endpoint detection and response (EDR) alerts with DNS logs to identify potential data exfiltration. The EDR alerts include process names and file paths, while DNS logs include domain names and IP addresses. The analyst has normalized both data sources to a common schema. Which additional step is most important to identify a relationship between a specific process and a suspicious domain?
Select an answer first - 34
A large organization collects threat data from multiple sources: a commercial feed that provides IoCs in STIX format, an open-source feed that provides CSV files, and internal logs in JSON. The team wants to correlate these data to identify a potential campaign. They have noticed that the commercial feed uses a different timestamp format than the internal logs. What is the most critical first step to enable effective correlation?
Select an answer first - 35
An incident response team has observed a series of attacks that appear to follow a specific pattern: initial access via a vulnerable web application, privilege escalation using a known exploit, and data exfiltration via encrypted channels. The team wants to develop countermeasures that address the entire attack chain. What is the most effective approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.