
EC-CouncilThreat Intelligence Essentials
Domain 7Objective 2
The Threat Hunting Process TIE Practice Questions (Page 1)
Part of the Threat Hunting and Detection domain, which makes up ~12% of our current practice bank.
46questions here
10free pages
6concepts
Questions 1–5
- 1
Which type of data is most commonly used in threat hunting to validate a hypothesis?
Select an answer first - 2
A threat hunter is investigating a hypothesis that an attacker is using living-off-the-land binaries (LOLBins) to move laterally. The hunter has access to Windows Event Logs, Sysmon, and network logs, but the environment has a high volume of legitimate PowerShell and WMI activity. How should the hunter analyze the data to validate the hypothesis without being overwhelmed by false positives?
Select an answer first - 3
A threat hunter has just completed a hunt that confirmed a malware infection on a single workstation. The hunter has documented the findings and reported them to the incident response team. What is the final step in the threat hunting process that the hunter should perform?
Select an answer first - 4
What is the main goal of analyzing collected data during a threat hunt?
Select an answer first - 5
A threat hunter at a healthcare organization is planning a hunt for ransomware activity. The organization has a mature SIEM and EDR, but recent attacks in the industry have used legitimate remote management tools (RMM) to perform malicious actions. The hunter must decide which hypothesis to pursue with limited resources. Which hypothesis is most likely to reduce dwell time and detect the threat?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.