
EC-CouncilThreat Intelligence Essentials
Domain 2Objective 5
Integrating Threat Intelligence with Risk Management TIE Practice Questions (Page 4)
Part of the Types of Threat Intelligence domain, which makes up ~11% of our current practice bank.
43questions here
9free pages
5concepts
Questions 16–20
- 16
A small online retailer has a legacy customer database that is no longer used by any application but still contains sensitive customer data. Threat intelligence indicates that this type of data is a prime target for ransomware groups. The retailer is considering risk treatment options. Which option best aligns with the threat intelligence insight?
Select an answer first - 17
A regional bank is updating its annual risk assessment. The CISO wants to incorporate current threat intelligence to better estimate the likelihood of a ransomware attack. The bank has historical loss data for past incidents, but the threat landscape has shifted significantly. Which approach best integrates threat intelligence into the risk assessment?
Select an answer first - 18
An e-commerce company uses a threat-informed risk scoring model where each risk is scored as likelihood × impact. A threat intelligence report reveals that a new exploit kit is targeting the company's content management system (CMS) version. The exploit kit is easy to use and has a high success rate. How should the company adjust the risk score for the CMS vulnerability?
Select an answer first - 19
When an organization decides to purchase cyber insurance to cover losses from a specific threat, which risk treatment option are they applying?
Select an answer first - 20
How does a qualitative risk assessment methodology typically incorporate threat intelligence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.