Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 6Objective 5

Reporting, Communicating, and Visualizing Findings TIE Practice Questions (Page 6)

Part of the Threat Intelligence Analysis domain, which makes up ~14% of our current practice bank.

47questions here
10free pages
7concepts

Questions 26–30

  1. 26application · medium

    After delivering a monthly threat intelligence report, the analyst receives feedback from the incident response team that the 'Indicators of Compromise' section is too long and includes many IOCs that are not relevant to their current environment. The executive team also comments that the 'Executive Summary' is too technical. How should the analyst incorporate this feedback?

    Select an answer first
  2. 27expert · hard

    A threat intelligence team uses a commercial TIP that has a built-in dashboard feature. The team also has access to an open-source visualization tool like Gephi. The team needs to create a complex network graph of threat actor relationships for a deep-dive analysis, but the TIP's built-in graph feature is limited. What is the best approach?

    Select an answer first
  3. 28expert · hard

    An analyst has a dataset of 10,000 phishing URLs, each tagged with the threat actor, target industry, and date. The analyst needs to present this data to a non-technical audience to show which industries are most targeted and by which actors. The audience is not familiar with technical jargon. What is the best visualization approach?

    Select an answer first
  4. 29foundation · easy

    Which section of a threat intelligence report is primarily intended to provide a quick overview of the key findings, conclusions, and recommended actions for readers who may not have time to read the full document?

    Select an answer first
  5. 30application · medium

    An analyst has collected a large dataset of malicious domains and their associated threat actor groups. The analyst must present this data to a non-technical audience in a way that highlights the most active threat actors. What is the best way to present this data?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.