Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 1Objective 2

Key Differences Between Intelligence, Information, and Data TIE Practice Questions (Page 5)

Part of the Introduction to Threat Intelligence domain, which makes up ~14% of our current practice bank.

38questions here
8free pages
6concepts

Questions 21–25

  1. 21application · medium

    A security analyst has collected a set of IP addresses that have been scanning the company's external firewall. The analyst checks a threat feed and finds that these IPs are known command-and-control servers for a specific botnet. The analyst then writes a memo to the SOC manager stating that the scanning activity is likely a precursor to a botnet infection and recommends increasing monitoring on internal hosts. Which element of this scenario is best classified as intelligence?

    Select an answer first
  2. 22application · medium

    A threat intelligence analyst is asked to provide the SOC with a daily list of malicious domains. The analyst pulls the list from a commercial feed, filters out domains that are not relevant to the company's industry, and adds a note explaining which domains are associated with recent phishing campaigns. The SOC uses this list to update their blocklist. Which statement best describes the analyst's output?

    Select an answer first
  3. 23application · medium

    An organization's threat intelligence team is building a process to turn raw telemetry into actionable intelligence. They have defined the following steps: (1) collect raw logs, (2) filter and normalize the logs, (3) correlate the logs with threat feeds, (4) analyze the correlated data to identify attack patterns, and (5) produce a report with recommended countermeasures. At which step does the process transition from information to intelligence?

    Select an answer first
  4. 24application · medium

    A threat intelligence analyst is preparing a brief for the CISO. The brief includes: a list of recent malware hashes, a summary of which systems in the organization were infected, and a recommendation to apply a specific patch to close the vulnerability exploited by the malware. Which part of the brief is intelligence?

    Select an answer first
  5. 25foundation · easy

    A security team collects IP addresses from firewall logs (Step 1), then groups them by country and flags those from known hostile regions (Step 2), and finally produces a report recommending which IPs to block based on correlation with active campaigns (Step 3). Which sequence correctly identifies the stages?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.