Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 7Objective 4

Forming Threat Hunting Hypotheses TIE Practice Questions (Page 4)

Part of the Threat Hunting and Detection domain, which makes up ~12% of our current practice bank.

31questions here
7free pages
7concepts

Questions 16–20

  1. 16application · medium

    A threat intelligence report describes a campaign that uses spear-phishing emails with a malicious Excel macro to drop Cobalt Strike, followed by lateral movement via SMB and eventual data staging in a cloud storage share. The security team wants to hunt for this activity in their environment. Which hypothesis best leverages this intelligence?

    Select an answer first
  2. 17foundation · easy

    Which of the following is a valid way to use threat intelligence to form a hypothesis?

    Select an answer first
  3. 18expert · hard

    A security team has limited resources and must choose between two hypotheses: (1) a known APT group is targeting the organization's research and development team via spear-phishing, and (2) a disgruntled employee is exfiltrating sensitive data via personal cloud storage. The team has threat intelligence on the APT group but no evidence of insider activity. Which hypothesis should be prioritized?

    Select an answer first
  4. 19expert · hard

    A threat hunting team has three hypotheses to investigate: (1) a known ransomware group is using a specific phishing campaign, (2) an insider is stealing intellectual property via email, and (3) a vulnerable VPN appliance is being exploited. The team has limited time and must choose one hypothesis to hunt. Which hypothesis should they choose?

    Select an answer first
  5. 20expert · hard

    A threat hunting team has limited time and resources. They have three hypotheses: (1) a known APT group is using a specific phishing lure against executives, (2) an insider is exfiltrating data via USB drives, and (3) a vulnerable internet-facing application is being exploited for initial access. Which hypothesis should the team prioritize first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.