Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 4Objective 4

Normalizing, Enriching, and Extracting Useful Intelligence TIE Practice Questions (Page 2)

Part of the Data Collection and Sources domain, which makes up ~13% of our current practice bank.

38questions here
8free pages
3concepts

Questions 6–10

  1. 6application · medium

    A threat intelligence team has collected a large amount of data from various sources, including social media, forums, and technical reports. The team needs to identify emerging threats that are relevant to the organization. Which approach would best support the extraction of emerging threats?

    Select an answer first
  2. 7expert · hard

    A threat intelligence team is responsible for producing a daily threat summary for a large enterprise. The team has a limited budget and cannot afford a commercial threat intelligence platform. They have access to open-source feeds, a SIEM, and a free WHOIS service. The team needs to extract actionable intelligence efficiently. What is the most effective approach?

    Select an answer first
  3. 8application · medium

    A SOC analyst has a list of 10,000 indicators from various sources. The analyst needs to identify which indicators are most likely to be used in an imminent attack against the organization's network. The data has been normalized and enriched. What is the most effective method to extract the most relevant indicators?

    Select an answer first
  4. 9application · medium

    An analyst has a list of suspicious IP addresses that triggered alerts on the organization's perimeter firewall. The analyst needs to determine which of these IPs are associated with known malicious infrastructure and which are simply false positives from legitimate services. The analyst has access to a commercial threat intelligence feed, WHOIS data, and geolocation services. What is the most effective way to enrich the IP addresses?

    Select an answer first
  5. 10application · medium

    An analyst is investigating a phishing campaign that uses a newly registered domain. The analyst has the domain name and wants to determine the registrant's identity and whether the domain is associated with known malicious activity. Which enrichment sources would be most useful for this investigation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.