
EC-CouncilThreat Intelligence Essentials
Domain 3Objective 2
Emerging Threats, Threat Actors, and Attack Vectors TIE Practice Questions (Page 6)
Part of the Cyber Threat Landscape domain, which makes up ~11% of our current practice bank.
39questions here
8free pages
3concepts
Questions 26–30
- 26
A small business has a website that allows users to upload profile pictures. Recently, attackers have been uploading files that contain malicious scripts, and when other users view the profiles, the scripts execute in their browsers. Which attack vector is being exploited?
Select an answer first - 27
A software development company uses a public code repository to host some of its open-source projects. A developer accidentally commits a file containing AWS access keys. Within hours, the company notices unusual activity in their AWS account. What is the most likely attack vector that was exploited?
Select an answer first - 28
A regional hospital's IT team notices an increasing number of phishing emails that contain realistic-looking but fake Microsoft 365 login pages. The emails are personalized with the recipient's name and job title, and they reference recent internal projects. The hospital's security team wants to reduce the risk of credential theft. Which combination of actions would be most effective?
Select an answer first - 29
A regional hospital's security team notices an increase in phishing emails that contain realistic-looking but fake invoices from a known medical supplier. The emails include a link to a credential-harvesting page that mimics the supplier's portal. The team suspects a specific threat actor. Which combination of threat actor profile and attack vector best matches this scenario?
Select an answer first - 30
Which characteristic is most typical of a ransomware-as-a-service (RaaS) operation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.