
EC-CouncilThreat Intelligence Essentials
Domain 4Objective 4
Normalizing, Enriching, and Extracting Useful Intelligence TIE Practice Questions (Page 5)
Part of the Data Collection and Sources domain, which makes up ~13% of our current practice bank.
38questions here
8free pages
3concepts
Questions 21–25
- 21
A multinational company's SOC receives threat intelligence from multiple sources, including a commercial feed that uses STIX/TAXII, an open-source feed that provides CSV files, and internal sensors that output JSON. The SOC wants to correlate indicators of compromise (IOCs) across these sources to detect attacks. The team has limited engineering resources and needs a solution that can be implemented quickly. Which approach best balances the need for consistency and the limited resources?
Select an answer first - 22
A security operations center (SOC) receives threat data from multiple sources: firewall logs that record IP addresses in dotted-decimal, DNS logs that use fully qualified domain names, and a threat intelligence feed that uses CIDR notation. Analysts are struggling to correlate events because the same host appears in different formats across sources. The SOC manager wants a single, unified view for analysis. Which approach should the analyst take first?
Select an answer first - 23
A threat intelligence team has a large volume of indicators that have been normalized and enriched. The team needs to produce a report for the board of directors that highlights the top threats to the organization. The team has limited time and must ensure the report is accurate and relevant. What is the most effective way to extract the intelligence for this report?
Select an answer first - 24
A threat intelligence team has a large dataset of indicators that have been normalized and enriched. The team needs to provide a weekly report to the CISO that summarizes the top threats and recommends actions. What is the most effective way to extract the intelligence for this report?
Select an answer first - 25
An analyst has a list of suspicious domains from network logs. Which enrichment source would provide the most direct information about the domain's registration owner and contact details?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.