
EC-CouncilThreat Intelligence Essentials
Domain 8Objective 1
Importance of Information Sharing Initiatives TIE Practice Questions (Page 1)
Part of the Sharing, Collaboration, and Incident Response domain, which makes up ~13% of our current practice bank.
47questions here
10free pages
7concepts
Questions 1–5
- 1
A large retail chain is a member of a retail ISAC and receives a TLP:AMBER alert about a new point-of-sale (POS) malware campaign. The alert includes YARA rules and network indicators. The chain's SOC wants to deploy the YARA rules to endpoint detection tools and block the network indicators at the firewall. However, the SOC is concerned that the YARA rules may cause false positives on legitimate POS software. The CISO wants to act quickly but also avoid disrupting business operations. What is the best course of action?
Select an answer first - 2
During an active ransomware incident, a manufacturing company receives a TLP:RED alert from its sector ISAC containing the attacker's C2 infrastructure and encryption indicators. How should the company's incident response team use this information to improve its response?
Select an answer first - 3
A security operations center (SOC) analyst receives a STIX bundle from a partner organization. The analyst needs to extract the IP addresses and file hashes to create detection rules. What is the primary advantage of receiving this intelligence in STIX format?
Select an answer first - 4
A new cybersecurity startup wants to contribute to the threat intelligence community but has limited resources and no existing relationships. The startup's goal is to both receive intelligence and build a reputation as a responsible sharer. Which approach is most aligned with this goal?
Select an answer first - 5
What is the purpose of the Traffic Light Protocol (TLP) in information sharing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.