
EC-CouncilThreat Intelligence Essentials
Domain 1Objective 2
Key Differences Between Intelligence, Information, and Data TIE Practice Questions (Page 5)
Part of the Introduction to Threat Intelligence domain, which makes up ~14% of our current practice bank.
38questions here
8free pages
6concepts
Questions 21–25
- 21
A security analyst has collected a set of IP addresses that have been scanning the company's external firewall. The analyst checks a threat feed and finds that these IPs are known command-and-control servers for a specific botnet. The analyst then writes a memo to the SOC manager stating that the scanning activity is likely a precursor to a botnet infection and recommends increasing monitoring on internal hosts. Which element of this scenario is best classified as intelligence?
Select an answer first - 22
A threat intelligence analyst is asked to provide the SOC with a daily list of malicious domains. The analyst pulls the list from a commercial feed, filters out domains that are not relevant to the company's industry, and adds a note explaining which domains are associated with recent phishing campaigns. The SOC uses this list to update their blocklist. Which statement best describes the analyst's output?
Select an answer first - 23
An organization's threat intelligence team is building a process to turn raw telemetry into actionable intelligence. They have defined the following steps: (1) collect raw logs, (2) filter and normalize the logs, (3) correlate the logs with threat feeds, (4) analyze the correlated data to identify attack patterns, and (5) produce a report with recommended countermeasures. At which step does the process transition from information to intelligence?
Select an answer first - 24
A threat intelligence analyst is preparing a brief for the CISO. The brief includes: a list of recent malware hashes, a summary of which systems in the organization were infected, and a recommendation to apply a specific patch to close the vulnerability exploited by the malware. Which part of the brief is intelligence?
Select an answer first - 25
A security team collects IP addresses from firewall logs (Step 1), then groups them by country and flags those from known hostile regions (Step 2), and finally produces a report recommending which IPs to block based on correlation with active campaigns (Step 3). Which sequence correctly identifies the stages?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.