Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 4Objective 4

Normalizing, Enriching, and Extracting Useful Intelligence TIE Practice Questions (Page 8)

Part of the Data Collection and Sources domain, which makes up ~13% of our current practice bank.

38questions here
8free pages
3concepts

Questions 36–38

  1. 36expert · hard

    A security analyst is investigating a suspicious domain that has been used in a phishing campaign. The analyst has the domain name and wants to understand the infrastructure behind it, including the hosting provider and any related domains. The analyst has access to WHOIS, passive DNS, and a commercial threat intelligence feed. The analyst has limited time and needs to prioritize the enrichment sources. Which combination of sources would provide the most comprehensive picture in the shortest time?

    Select an answer first
  2. 37expert · hard

    A company is integrating a new threat intelligence feed that provides data in a proprietary XML format. The company's existing TIP uses a JSON schema. The team needs to ingest the new feed and make it available for analysis. However, the team also needs to maintain the original XML data for compliance. What is the best approach?

    Select an answer first
  3. 38foundation · easy

    A threat intelligence analyst receives raw logs from multiple sources: some use JSON, some use CSV, and some use XML. The analyst needs to combine these logs into a single dataset for analysis. What is the primary purpose of normalizing this raw data?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to TIE

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.