Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 4Objective 4

Normalizing, Enriching, and Extracting Useful Intelligence TIE Practice Questions (Page 7)

Part of the Data Collection and Sources domain, which makes up ~13% of our current practice bank.

38questions here
8free pages
3concepts

Questions 31–35

  1. 31application · medium

    An analyst has identified a suspicious file hash from a malware sample. The analyst wants to determine if this hash is associated with a known threat actor group and what type of malware it is. Which enrichment sources would provide the most relevant context?

    Select an answer first
  2. 32expert · hard

    A multinational organization has a threat intelligence platform that ingests data from multiple sources, including internal logs, commercial feeds, and open-source feeds. The data is stored in a data lake. The team has noticed that the same IP address appears in different formats: some sources use dotted-decimal, some use integer, and some use CIDR. The team also has a requirement to preserve the original raw data for compliance purposes. The team needs to enable efficient correlation and analysis while maintaining the raw data. What is the best approach?

    Select an answer first
  3. 33application · medium

    A security team is consolidating threat intelligence from multiple sources into a single repository. The sources use different formats for IP addresses, including IPv4, IPv6, and CIDR notation. The team needs to ensure that all IP addresses can be queried consistently. What should the team do?

    Select an answer first
  4. 34application · medium

    A threat intelligence team is tasked with identifying which indicators from a large dataset are most relevant to the organization's current security posture. The dataset includes indicators from various sources, some of which are outdated. Which approach would best help the team extract the most useful intelligence?

    Select an answer first
  5. 35application · medium

    A security team is integrating a new threat intelligence feed that provides indicators in STIX/TAXII format. The team's existing TIP uses a custom JSON schema. The team needs to ingest the new feed without disrupting existing workflows. What is the first step the team should take?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.