
EC-CouncilThreat Intelligence Essentials
Domain 3Objective 4
The Cyber Kill Chain Methodology TIE Practice Questions (Page 5)
Part of the Cyber Threat Landscape domain, which makes up ~11% of our current practice bank.
25questions here
5free pages
4concepts
Questions 21–25
- 21
In the Cyber Kill Chain, what is the primary purpose of the Weaponization phase?
Select an answer first - 22
A threat intelligence analyst is writing a report on an attack that used a supply-chain compromise. The attacker compromised a software vendor and injected malicious code into a legitimate update. The update was distributed to many organizations. The analyst is trying to map this to the Cyber Kill Chain. Which phase is most directly associated with the compromised update?
Select an answer first - 23
A penetration tester is simulating an attack for a client. The tester has identified a vulnerability in the client's web application and has crafted a custom exploit payload. According to the Cyber Kill Chain, which phase is the tester currently in?
Select an answer first - 24
A security team is considering using the Cyber Kill Chain to model a potential insider threat scenario where an employee with legitimate access exfiltrates data. Which limitation of the Cyber Kill Chain is most relevant to this scenario?
Select an answer first - 25
A threat hunter is reviewing network logs and identifies a series of DNS queries to a domain that is known to be a command-and-control server. The hunter also notices that the compromised host has been sending large amounts of data to an external IP address. Which two phases of the Cyber Kill Chain are the hunter observing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to TIE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.