
EC-CouncilThreat Intelligence Essentials
Domain 3Objective 5
Indicators of Compromise (IoC) and MITRE ATT&CK TIE Practice Questions (Page 6)
Part of the Cyber Threat Landscape domain, which makes up ~11% of our current practice bank.
39questions here
8free pages
6concepts
Questions 26–30
- 26
A security operations center (SOC) wants to improve its detection capabilities by moving from a purely signature-based approach to a behavior-based approach. The team has access to MITRE ATT&CK and a SIEM that can ingest logs from endpoints and network devices. Which strategy best leverages ATT&CK to achieve this goal?
Select an answer first - 27
A threat intelligence analyst is correlating IoCs from multiple sources. One source reports a file hash as associated with a banking trojan. Another source reports the same hash as associated with a ransomware family. The analyst needs to map the hash to MITRE ATT&CK techniques. Which approach is most appropriate?
Select an answer first - 28
A security team has been using a list of file hashes from a third-party feed to block malware. Over time, they notice an increasing number of false positives and missed detections. The team suspects the IoCs are outdated. What is the best way to manage the IoC lifecycle to address this issue?
Select an answer first - 29
A security analyst is reviewing a threat intelligence report that lists the following IoCs: a malicious IP address, a file hash, and a registry key. The analyst wants to map these IoCs to MITRE ATT&CK techniques. Which approach is most effective?
Select an answer first - 30
What is the final stage in the lifecycle of an Indicator of Compromise (IoC)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.