
EC-CouncilThreat Intelligence Essentials
Domain 7Objective 2
The Threat Hunting Process TIE Practice Questions (Page 3)
Part of the Threat Hunting and Detection domain, which makes up ~12% of our current practice bank.
46questions here
10free pages
6concepts
Questions 11–15
- 11
A security analyst at a mid-sized firm notices a spike in outbound DNS queries to a domain that was recently flagged in a threat intelligence feed as a known C2 infrastructure. The analyst wants to start a threat hunt to determine if any host is actually communicating with that domain. Which initial step best aligns with the threat hunting process?
Select an answer first - 12
A threat hunter is planning a hunt for a suspected insider threat who may be exfiltrating data via USB drives. The hunter has access to endpoint logs, data loss prevention (DLP) alerts, and physical access logs. The hunter must avoid alerting the suspected insider while gathering enough evidence. Which approach best balances stealth and thoroughness?
Select an answer first - 13
A security analyst at a mid-sized firm notices that several employees have received spear-phishing emails referencing a recent internal project. The emails contain no malicious attachments or links, but the analyst suspects reconnaissance. The analyst wants to proactively hunt for signs that the attackers have already established a foothold. Which approach best aligns with the threat hunting process?
Select an answer first - 14
A threat hunter is testing the hypothesis that 'an attacker is using PowerShell to download and execute payloads on Windows endpoints.' The hunter has access to Windows Event Logs, Sysmon logs, and network proxy logs. Which data collection and analysis approach would most effectively validate or refute this hypothesis?
Select an answer first - 15
A threat hunter is planning a hunt based on a recent vulnerability disclosure. The hunter has limited time and wants to follow a structured process. What is the correct sequence of steps for this hunt?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.