
EC-CouncilThreat Intelligence Essentials
Domain 7Objective 4
Forming Threat Hunting Hypotheses TIE Practice Questions (Page 5)
Part of the Threat Hunting and Detection domain, which makes up ~12% of our current practice bank.
31questions here
7free pages
7concepts
Questions 21–25
- 21
A security team is new to threat hunting and wants to adopt a structured approach. They have a large amount of log data and want to avoid random searches. Which approach best exemplifies hypothesis-driven hunting?
Select an answer first - 22
A threat hunter has formulated a hypothesis about potential lateral movement using PsExec. The hunter needs to document and communicate this hypothesis effectively. Which of the following elements should be included in the documentation? (Select all that apply.)
Select an answer first - 23
A threat hunter is investigating a potential credential theft incident. They observe that a user account is being used to access multiple systems in a short period, which is unusual for that user. Which MITRE ATT&CK technique should be central to the hypothesis?
Select an answer first - 24
A threat hunter has formulated a hypothesis that a specific user account is being used for unauthorized access based on unusual logon patterns. The hunter needs to communicate this to the incident response team and management. What is the most effective way to document and communicate the hypothesis?
Select an answer first - 25
When prioritizing hypotheses, which factor should be considered to focus hunting efforts effectively?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.