
EC-CouncilThreat Intelligence Essentials
Domain 8Objective 4
Legal and Privacy Implications of Sharing Threat Intelligence TIE Practice Questions (Page 2)
Part of the Sharing, Collaboration, and Incident Response domain, which makes up ~13% of our current practice bank.
40questions here
8free pages
6concepts
Questions 6–10
- 6
A company in the healthcare sector wants to share threat intelligence with a research institution in another country. The data includes IP addresses of systems that store patient records. The company is subject to HIPAA and the other country's data protection law. What is the most important consideration before sharing?
Select an answer first - 7
A security analyst is preparing a threat intelligence report for a public conference. The report includes a case study of a phishing attack that targeted a specific company. The analyst wants to share the technical details without revealing the company's identity. What is the best approach?
Select an answer first - 8
A financial institution is sharing a set of malicious IP addresses with a sector-specific information sharing and analysis center (ISAC). The IPs are associated with a botnet that also infected a few customer-facing kiosks. The institution wants to protect customer privacy while still allowing the ISAC to correlate the IPs with other attacks. Which technique best meets this requirement?
Select an answer first - 9
A global bank is negotiating a threat intelligence sharing agreement with a fintech partner. The bank requires that the partner not use the shared indicators for any purpose other than defending its own network. The partner wants to use the indicators to improve its commercial threat detection product. The bank also wants to ensure that if the partner suffers a breach, the bank is not liable. Which agreement structure best meets the bank's requirements?
Select an answer first - 10
An organization is about to share threat intelligence that could potentially be used by the recipient to identify and take action against a suspected attacker who may be an innocent victim of a compromised system. What ethical consideration should guide the sharing decision?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.