Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 4Objective 4

Normalizing, Enriching, and Extracting Useful Intelligence TIE Practice Questions (Page 6)

Part of the Data Collection and Sources domain, which makes up ~13% of our current practice bank.

38questions here
8free pages
3concepts

Questions 26–30

  1. 26expert · hard

    A security operations center (SOC) receives threat data from multiple sources in different formats. The SOC uses a SIEM that requires data to be in a specific schema. The team has a data pipeline that ingests raw data and needs to normalize it before sending it to the SIEM. However, the team also needs to preserve the original raw data for forensic investigations. What is the best way to design the pipeline?

    Select an answer first
  2. 27application · medium

    A security analyst is reviewing a large dataset of network flows to identify potential command-and-control (C2) communication. The dataset contains millions of records, and the analyst needs to quickly identify the most suspicious connections for further investigation. Which approach would best support the extraction of actionable intelligence from this dataset?

    Select an answer first
  3. 28application · medium

    A security team is ingesting threat intelligence from multiple sources, including a STIX/TAXII feed, a CSV file, and a JSON API. The team wants to store all indicators in a single database for querying. Which normalization step is essential before loading the data into the database?

    Select an answer first
  4. 29application · medium

    An analyst is investigating a series of attacks targeting the company's web servers. The analyst has the source IP addresses of the attacks and wants to understand the attacker's infrastructure and potential motivation. Which enrichment would provide the most useful context for this investigation?

    Select an answer first
  5. 30foundation · easy

    During an investigation, an analyst extracts an IP address from a phishing email. To increase the value of this raw indicator, the analyst looks up the IP's geolocation, WHOIS registration details, and checks it against known threat intelligence feeds. What is this process called?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.