Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 2Objective 5

Integrating Threat Intelligence with Risk Management TIE Practice Questions (Page 9)

Part of the Types of Threat Intelligence domain, which makes up ~11% of our current practice bank.

43questions here
9free pages
5concepts

Questions 41–43

  1. 41expert · hard

    A software company has a critical vulnerability in a product that is widely used by its customers. Threat intelligence shows that exploit code is publicly available. The company has limited resources and must decide how to treat the risk. Which option is the most balanced approach?

    Select an answer first
  2. 42application · medium

    A regional bank uses a qualitative risk assessment with a 5x5 likelihood-impact matrix. After a threat intelligence report indicates a surge in phishing campaigns targeting banks in the same jurisdiction, the risk owner wants to reflect this in the risk register. The bank's current phishing risk is rated 'Medium' (likelihood 3, impact 3). Which action best applies the threat intelligence to the risk assessment?

    Select an answer first
  3. 43expert · hard

    A large enterprise has a continuous monitoring process that updates risk scores based on threat intelligence. The process currently uses a manual review of threat feeds every 48 hours. The security team wants to improve the process to respond faster to emerging threats. Which improvement would be most effective?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to TIE

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.