Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 2Objective 5

Integrating Threat Intelligence with Risk Management TIE Practice Questions (Page 7)

Part of the Types of Threat Intelligence domain, which makes up ~11% of our current practice bank.

43questions here
9free pages
5concepts

Questions 31–35

  1. 31application · medium

    A government agency has a risk management process that is updated annually. After a series of cyberattacks on other agencies, threat intelligence indicates that similar attacks are likely. The agency wants to improve its responsiveness. Which action is most effective?

    Select an answer first
  2. 32application · medium

    A retail company has a risk management process that updates risk scores annually. After a major data breach in the industry, threat intelligence indicates that similar attacks are increasing. The CISO wants to implement a more responsive process. Which change is most effective?

    Select an answer first
  3. 33expert · hard

    A multinational corporation uses a threat-informed risk scoring model where risk = likelihood × impact. A threat intelligence report indicates that a specific Advanced Persistent Threat (APT) group is targeting the company's intellectual property. The APT is known for using spear-phishing and zero-day exploits. The company has a strong security awareness program but cannot patch all systems immediately. Which adjustment to the risk score is most appropriate?

    Select an answer first
  4. 34application · medium

    A logistics company has a critical application that is essential for daily operations. Threat intelligence indicates a specific malware strain is targeting the application's underlying operating system, and the vendor has released a patch. The company's change management process requires a two-week testing period before deploying patches. What is the most appropriate risk treatment option?

    Select an answer first
  5. 35expert · hard

    A company is deciding between a quantitative and a qualitative risk assessment methodology. They have some historical data but it is incomplete and not fully reliable. Threat intelligence provides current information about active threats. Which methodology is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.