Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 1Objective 3

Integrating Threat Intelligence in Cyber Operations TIE Practice Questions (Page 5)

Part of the Introduction to Threat Intelligence domain, which makes up ~14% of our current practice bank.

39questions here
8free pages
5concepts

Questions 21–25

  1. 21expert · hard

    A SOC has implemented an automated threat intelligence feed that blocks IP addresses at the firewall. However, they are experiencing a high number of false positives, blocking legitimate business partners. They want to reduce false positives without losing the benefits of automation. What is the best approach?

    Select an answer first
  2. 22application · medium

    After a security incident, the incident response team discovers that a threat actor used a new command-and-control (C2) domain that was not in the organization's threat intelligence feed. The team wants to improve future detection. What should they do to close this gap?

    Select an answer first
  3. 23foundation · easy

    Which practice best supports a continuous improvement feedback loop for threat intelligence?

    Select an answer first
  4. 24foundation · easy

    How can threat intelligence help prioritize threats in a cyber operations environment?

    Select an answer first
  5. 25expert · hard

    A company wants to automate response actions based on threat intelligence, but they are concerned about the risk of automated actions causing unintended damage. They want to implement automation while maintaining human oversight. Which approach best balances automation and control?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.