
EC-CouncilThreat Intelligence Essentials
Domain 3Objective 5
Indicators of Compromise (IoC) and MITRE ATT&CK TIE Practice Questions (Page 2)
Part of the Cyber Threat Landscape domain, which makes up ~11% of our current practice bank.
39questions here
8free pages
6concepts
Questions 6–10
- 6
A security analyst is reviewing a threat intelligence report that describes an adversary using PowerShell to download and execute a payload. The report also mentions that the adversary uses obfuscation to hide the script. How should the analyst categorize this behavior using MITRE ATT&CK?
Select an answer first - 7
A red team exercise is being planned to test the organization's detection capabilities. The blue team wants to use MITRE ATT&CK to evaluate which adversary behaviors they can detect. Which approach best uses ATT&CK for this purpose?
Select an answer first - 8
What is the primary purpose of an Indicator of Compromise (IoC) in cybersecurity?
Select an answer first - 9
A security architect is designing a detection program for a financial institution. The institution is subject to strict compliance requirements and has a limited security budget. The architect wants to use MITRE ATT&CK to improve detection coverage. Which approach best balances compliance, cost, and effectiveness?
Select an answer first - 10
A security operations team receives a daily feed of IoCs from a commercial threat intelligence provider. The feed includes IP addresses, domains, and file hashes. The team automatically blocks all IPs and domains in the feed. After a few weeks, they notice that some internal users are unable to access a legitimate cloud service. What is the most likely cause?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.