
EC-CouncilThreat Intelligence Essentials
Domain 4Objective 5
Legal and Ethical Considerations for Threat Data Collection TIE Practice Questions (Page 6)
Part of the Data Collection and Sources domain, which makes up ~13% of our current practice bank.
55questions here
11free pages
10concepts
Questions 26–30
- 26
During incident response, a forensic analyst collects a memory dump that contains chat messages and credentials of employees. The organization is subject to GDPR. What is the best practice for handling this sensitive data?
Select an answer first - 27
What is the primary purpose of applying data anonymization techniques to threat intelligence data?
Select an answer first - 28
A threat intelligence platform provides a feed of indicators of compromise (IOCs) under a Creative Commons Attribution license. What does this license allow you to do?
Select an answer first - 29
A security operations center (SOC) is collecting threat data from various sources, including email headers from phishing attacks. The email headers contain the email addresses of the victims and the attackers. The SOC wants to use this data to improve detection rules. What should the SOC do to adhere to ethical principles?
Select an answer first - 30
A threat intelligence analyst at a security vendor has access to a dark web forum where cybercriminals discuss upcoming attacks. The analyst can monitor the forum without participating, but to gain deeper access, they would need to create an account and post messages that encourage criminals to reveal more details. The analyst's goal is to gather actionable intelligence to protect clients. What is the most ethical course of action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.