
EC-CouncilThreat Intelligence Essentials
Domain 7Objective 2
The Threat Hunting Process TIE Practice Questions (Page 8)
Part of the Threat Hunting and Detection domain, which makes up ~12% of our current practice bank.
46questions here
10free pages
6concepts
Questions 36–40
- 36
A threat hunter is testing the hypothesis that 'an attacker is using scheduled tasks to maintain persistence on Windows servers.' The hunter has access to Windows Event Logs, but the organization has a policy that limits the retention of logs to 30 days. The hunter suspects the attack may have started more than 30 days ago. What is the most effective way to test the hypothesis given this constraint?
Select an answer first - 37
A threat hunter is validating a hypothesis that a specific malware family is present in the environment. The hunter has collected a large amount of data, including process executions, file hashes, and network connections. The initial search for known IOCs returns no matches. What should the hunter do next?
Select an answer first - 38
A threat hunter is testing the hypothesis that 'an attacker is using RDP to move laterally between servers.' The hunter has access to Windows Security logs (Event ID 4624 for logon) and network flow logs. Which approach would best validate or refute this hypothesis?
Select an answer first - 39
A threat hunter is asked to hunt for a potential data breach involving customer data. The hunter has limited time and must choose between two hypotheses: (1) an external attacker exfiltrated data via the internet, or (2) an insider copied data to a personal cloud storage account. The hunter has access to firewall logs, DLP alerts, and endpoint logs. Which hypothesis should the hunter prioritize, and why?
Select an answer first - 40
A threat hunt concludes with no evidence of malicious activity, but the hunter noticed several configuration weaknesses that could be exploited in the future. What should the hunter do with these findings?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.