Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 6Objective 4

Leveraging Predictive and Proactive Threat Intelligence TIE Practice Questions (Page 5)

Part of the Threat Intelligence Analysis domain, which makes up ~14% of our current practice bank.

48questions here
10free pages
8concepts

Questions 21–25

  1. 21application · medium

    A security team wants to proactively hunt for a specific advanced persistent threat (APT) group that is known to use living-off-the-land binaries (LOLBins). The team has intelligence about the group's tactics, techniques, and procedures (TTPs). Which hunting approach is most effective?

    Select an answer first
  2. 22expert · medium

    A financial services company is developing a threat model for its new mobile banking application. Historical data shows that most attacks on similar apps come from credential stuffing, but the company's leadership is concerned about the reputational impact of a data breach. The security team has limited resources and must choose a defense priority. Which approach best balances predictive likelihood and potential impact in threat modeling?

    Select an answer first
  3. 23foundation · easy

    What is the benefit of integrating predictive and proactive threat intelligence in a security program?

    Select an answer first
  4. 24expert · hard

    A security analyst finds a suspicious IP address in a threat intelligence feed that is associated with a new malware campaign. The analyst wants to determine if the organization has been targeted and predict the campaign's next steps. However, the IP address is also used by a legitimate cloud service, causing false positives. Which action best balances the need to investigate with the risk of false positives?

    Select an answer first
  5. 25application · medium

    A security analyst finds a malicious IP address in a threat intelligence feed that is associated with a command-and-control server. The analyst wants to proactively hunt for any systems in the organization that may have communicated with this IP. Which action is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.