
EC-CouncilThreat Intelligence Essentials
Domain 7Objective 2
The Threat Hunting Process TIE Practice Questions (Page 7)
Part of the Threat Hunting and Detection domain, which makes up ~12% of our current practice bank.
46questions here
10free pages
6concepts
Questions 31–35
- 31
What is the primary purpose of formulating a hypothesis in threat hunting?
Select an answer first - 32
Which of the following is a primary goal of threat hunting?
Select an answer first - 33
A threat hunter is investigating a hypothesis that an attacker is using PowerShell to run encoded commands on a few servers. The hunter has access to Windows Event Logs, Sysmon, and network flow logs. Which data collection and analysis approach would most effectively validate or refute the hypothesis?
Select an answer first - 34
A threat hunter reads a threat intelligence report stating that a specific APT group is currently using a new DLL side-loading technique. The hunter wants to proactively search the environment for this activity. Which hypothesis is most testable and aligned with the intelligence?
Select an answer first - 35
A threat hunter has completed a hunt that successfully identified a new malware variant on a single endpoint. The hunter needs to report the findings to the security operations center (SOC) manager. What is the most important information to include in the report?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.