
EC-CouncilThreat Intelligence Essentials
Domain 4Objective 2
Data Collection Methods and Techniques TIE Practice Questions (Page 7)
Part of the Data Collection and Sources domain, which makes up ~13% of our current practice bank.
36questions here
8free pages
5concepts
Questions 31–35
- 31
A threat intelligence team needs to collect data on a sophisticated adversary that is known to monitor for active scanning. The team has a requirement to gather network-level indicators without being detected. They also need to collect data from a public forum that requires login. Which combination of techniques best satisfies both requirements?
Select an answer first - 32
A threat intelligence team is collecting data from multiple automated feeds. The team is experiencing a high rate of false positives, which is overwhelming the analysts. They have tried refining filters but the problem persists. What is the most effective next step to mitigate the false positive issue?
Select an answer first - 33
An organization is investigating a targeted attack that uses a custom backdoor. The team has limited time and must choose between collecting data from internal network logs or from a commercial threat intelligence feed. The internal logs are known to be incomplete, but the feed may not contain indicators for the custom backdoor. What is the best approach?
Select an answer first - 34
A small security team needs to collect threat intelligence on malware campaigns targeting their industry. They have a limited budget and no dedicated threat intelligence platform. Which collection method is most cost-effective and sustainable for their needs?
Select an answer first - 35
When selecting a data source for threat intelligence, which factor is most important to ensure the data is useful for decision-making?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.