
EC-CouncilThreat Intelligence Essentials
Domain 6Objective 5
Reporting, Communicating, and Visualizing Findings TIE Practice Questions (Page 5)
Part of the Threat Intelligence Analysis domain, which makes up ~14% of our current practice bank.
47questions here
10free pages
7concepts
Questions 21–25
- 21
A threat intelligence team produces a monthly report. The executive sponsor wants a one-page summary with clear business risk ratings. The SOC manager wants detailed IOCs and TTPs. The compliance team wants a section on regulatory implications. The team has limited time and must produce a single report. What is the best approach to satisfy all stakeholders?
Select an answer first - 22
An analyst has identified a critical vulnerability that is being exploited in the wild and affects a system that the organization uses. The analyst must communicate this to the system owner, who is not a security expert. What is the most effective way to communicate this finding?
Select an answer first - 23
An analyst has collected a large dataset of threat intelligence from multiple sources, including open-source feeds, commercial feeds, and internal telemetry. The data contains many false positives and duplicates. The analyst needs to present a clear and actionable summary to the security team. What is the most important step before creating the visualization?
Select an answer first - 24
A threat intelligence analyst uses a Python-based data analysis environment and wants to create a reusable, code-driven visualization of malware family relationships for a weekly report. The analyst needs a tool that integrates with the existing Python workflow and can produce publication-quality graphs. Which tool is most appropriate?
Select an answer first - 25
Which practice best supports the presentation of complex threat data in an actionable manner?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.