Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 3Objective 5

Indicators of Compromise (IoC) and MITRE ATT&CK TIE Practice Questions (Page 8)

Part of the Cyber Threat Landscape domain, which makes up ~11% of our current practice bank.

39questions here
8free pages
6concepts

Questions 36–39

  1. 36application · medium

    A malware analyst is reverse-engineering a new sample and discovers that it modifies a specific registry key to achieve persistence. The analyst also finds that the malware communicates with a unique domain. Which IoCs should the analyst include in the threat report?

    Select an answer first
  2. 37application · medium

    During an incident investigation, a security analyst observes that a malicious process is creating a scheduled task to run a script every hour. The analyst wants to document this behavior using MITRE ATT&CK. Which tactic and technique should the analyst map this activity to?

    Select an answer first
  3. 38application · medium

    A threat intelligence analyst is managing a list of IoCs in a TIP. One IoC is a file hash that was associated with a malware campaign that ended three months ago. The hash is no longer being seen in the wild, but the analyst is unsure whether to retire it. What is the most important factor in deciding whether to retire this IoC?

    Select an answer first
  4. 39foundation · easy

    Which of the following is an example of a host-based Indicator of Compromise (IoC)?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to TIE

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.