
EC-CouncilThreat Intelligence Essentials
Domain 1Objective 2
Key Differences Between Intelligence, Information, and Data TIE Practice Questions (Page 7)
Part of the Introduction to Threat Intelligence domain, which makes up ~14% of our current practice bank.
38questions here
8free pages
6concepts
Questions 31–35
- 31
Which of the following is the key characteristic that makes intelligence different from information?
Select an answer first - 32
A security operations center receives a high volume of raw alerts from multiple security tools. The SOC manager wants to reduce alert fatigue and improve the team's ability to respond to genuine threats. The manager asks an analyst to create a daily report that prioritizes alerts based on the organization's asset criticality and current threat landscape. Which approach best achieves this goal?
Select an answer first - 33
A threat intelligence analyst collects the following: (1) a list of IP addresses that attempted to connect to a honeypot, (2) a report stating that those IPs are associated with a known ransomware family, and (3) a recommendation to block those IPs at the perimeter because the organization's industry is a common target. Which sequence correctly orders these from data to intelligence?
Select an answer first - 34
A security analyst collects raw firewall logs and then sorts them by source IP and timestamp, adding labels for known internal subnets. What has the analyst produced?
Select an answer first - 35
What is the correct sequential transformation from raw inputs to decision-support products?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.