Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 1Objective 2

Key Differences Between Intelligence, Information, and Data TIE Practice Questions (Page 3)

Part of the Introduction to Threat Intelligence domain, which makes up ~14% of our current practice bank.

38questions here
8free pages
6concepts

Questions 11–15

  1. 11expert · hard

    A threat intelligence analyst is asked to provide the CISO with a recommendation on whether to block a set of IP addresses that have been observed scanning the organization's perimeter. The analyst has the following artifacts: (1) a list of the IP addresses, (2) a threat feed report indicating that the IPs are associated with a known scanning campaign, and (3) a previous incident report showing that similar scanning preceded a ransomware attack on a peer organization. The CISO wants a decision-support product, not just a summary. Which action should the analyst take to produce intelligence?

    Select an answer first
  2. 12foundation · easy

    Which statement best defines data in the context of threat intelligence?

    Select an answer first
  3. 13expert · hard

    A large organization is evaluating a threat intelligence platform. The platform ingests raw logs from multiple sources, automatically deduplicates and formats them, and then applies correlation rules to identify potential threats. The platform's output is a dashboard that shows alerts with recommended actions. The security team is debating whether the dashboard output is intelligence or information. Which argument is most accurate?

    Select an answer first
  4. 14expert · hard

    A threat intelligence team is designing a workflow to process raw network telemetry. The team has limited analyst time and must decide where to invest effort to maximize the production of actionable intelligence. The team has the following steps: (1) collect raw packets, (2) filter and normalize the packets into connection records, (3) enrich the records with threat intelligence feeds, (4) analyze the enriched records to identify malicious activity, and (5) write reports with recommended actions. Which step is most critical to ensure the final output is intelligence rather than just information?

    Select an answer first
  5. 15application · medium

    A threat intelligence analyst is reviewing a report from an external vendor that lists indicators of compromise (IOCs) for a new malware strain. The report includes file hashes, domains, and IP addresses, along with a note that these IOCs are associated with a campaign targeting the financial sector. The analyst's organization is in the financial sector. Which statement best describes the value of this report to the organization?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.