
EC-CouncilThreat Intelligence Essentials
Domain 3Objective 5
Indicators of Compromise (IoC) and MITRE ATT&CK TIE Practice Questions (Page 5)
Part of the Cyber Threat Landscape domain, which makes up ~11% of our current practice bank.
39questions here
8free pages
6concepts
Questions 21–25
- 21
A security team is evaluating a new EDR tool. The vendor claims that the tool is 'ATT&CK-aligned' and can detect all techniques. The team wants to verify this claim before purchasing. Which approach is most effective?
Select an answer first - 22
A security analyst at a mid-sized firm discovers a suspicious file on a workstation. The file's SHA-256 hash matches a known malware sample, and the analyst also observes the malware attempting to connect to a specific external IP address. The analyst wants to share these findings with the incident response team so they can check other systems for the same compromise. Which combination of IoCs should the analyst prioritize in the report?
Select an answer first - 23
In the MITRE ATT&CK framework, what does a 'tactic' represent?
Select an answer first - 24
A threat intelligence team maintains a list of malicious IP addresses and domains that were observed in a phishing campaign three months ago. The campaign has ended, and the infrastructure has been sinkholed. The team is deciding whether to keep these IoCs in their active blocklist. What is the most appropriate action according to IoC lifecycle management?
Select an answer first - 25
A security team wants to improve their detection capabilities by using MITRE ATT&CK. They have a SIEM that can ingest logs from endpoints and network devices. Which approach best leverages ATT&CK to improve detection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.