
EC-CouncilThreat Intelligence Essentials
Domain 7Objective 4
Forming Threat Hunting Hypotheses TIE Practice Questions (Page 3)
Part of the Threat Hunting and Detection domain, which makes up ~12% of our current practice bank.
31questions here
7free pages
7concepts
Questions 11–15
- 11
You are hunting for a threat actor that is known to use credential dumping (T1003) and lateral movement via SMB (T1021.002). You have a hypothesis that the actor is using these techniques on your Windows domain. Which MITRE ATT&CK tactic would you primarily associate with the credential dumping technique?
Select an answer first - 12
A security analyst notices an unusual pattern: several workstations are connecting to an internal file server at 3:00 AM, which is outside normal business hours. The analyst wants to start a threat hunt. Which approach best exemplifies hypothesis-driven hunting?
Select an answer first - 13
How can threat intelligence reports be used to generate threat hunting hypotheses?
Select an answer first - 14
Why is it important to base threat hunting hypotheses on knowledge of the organization's environment?
Select an answer first - 15
What is the defining characteristic of hypothesis-driven threat hunting?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.