Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 4Objective 4

Normalizing, Enriching, and Extracting Useful Intelligence TIE Practice Questions (Page 4)

Part of the Data Collection and Sources domain, which makes up ~13% of our current practice bank.

38questions here
8free pages
3concepts

Questions 16–20

  1. 16expert · hard

    A threat intelligence team has a large volume of raw data from multiple sources. The team needs to produce a prioritized list of indicators for the security operations team to block. The team has limited time and must ensure that the indicators are accurate and relevant. Which approach would best balance speed and accuracy?

    Select an answer first
  2. 17foundation · easy

    A threat intelligence team has collected and enriched a large volume of data. To extract actionable intelligence for decision-making, which criteria should the team prioritize?

    Select an answer first
  3. 18application · medium

    A threat intelligence analyst has extracted a list of suspicious IP addresses from a malware sandbox report. The analyst needs to determine which of these IPs are likely malicious and prioritize them for blocking. The analyst has access to a commercial threat intelligence feed, WHOIS data, and geolocation services. Which combination of actions would best enrich the IP addresses to support prioritization?

    Select an answer first
  4. 19application · medium

    A security operations center (SOC) ingests firewall logs, DNS logs, and proxy logs from three different vendors. The logs use different timestamp formats (Unix epoch, ISO 8601, and a vendor-specific format) and different IP address representations (IPv4 dotted-decimal, IPv6, and a vendor-specific integer format). Analysts are spending too much time correlating events across these sources. Which approach should the SOC take to reduce the time spent on correlation?

    Select an answer first
  5. 20application · medium

    A threat intelligence team has collected a large volume of raw data from open-source intelligence (OSINT), dark web forums, and internal security logs. The team needs to produce a daily intelligence summary for executives that highlights only the most relevant and actionable threats. Which process would best support the extraction of useful intelligence from this data?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.