
EC-CouncilThreat Intelligence Essentials
Domain 7Objective 4
Forming Threat Hunting Hypotheses TIE Practice Questions (Page 2)
Part of the Threat Hunting and Detection domain, which makes up ~12% of our current practice bank.
31questions here
7free pages
7concepts
Questions 6–10
- 6
A threat intelligence feed reports a new malware family that uses PowerShell to download additional payloads and then establishes persistence via scheduled tasks. The security team has limited logging on endpoints, but has network logs and Active Directory logs. Which hypothesis is most practical and testable given the available data?
Select an answer first - 7
In hypothesis-driven threat hunting, what role does the hypothesis play in the investigation process?
Select an answer first - 8
A company has a policy that all administrative tasks must be performed from a dedicated jump host. A threat hunter notices that an administrator account is logging in directly to a domain controller from a workstation. Which hypothesis is most aligned with environmental knowledge?
Select an answer first - 9
A threat intelligence report indicates that a specific adversary group is known to use living-off-the-land binaries (LOLBins) like certutil.exe to download payloads. The security team wants to hunt for this activity. Which hypothesis is best aligned with this intelligence?
Select an answer first - 10
How does the MITRE ATT&CK framework help in forming threat hunting hypotheses?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.