
EC-CouncilThreat Intelligence Essentials
Domain 7Objective 2
The Threat Hunting Process TIE Practice Questions (Page 9)
Part of the Threat Hunting and Detection domain, which makes up ~12% of our current practice bank.
46questions here
10free pages
6concepts
Questions 41–45
- 41
A threat hunter is testing the hypothesis that a specific user account is being used by an attacker during off-hours. The hunter has access to authentication logs, VPN logs, and endpoint activity logs. Which data analysis would most directly validate or refute this hypothesis?
Select an answer first - 42
Which of the following is an example of a well-formed threat hunting hypothesis?
Select an answer first - 43
A threat hunter notices that a legitimate application on several workstations is making unusual outbound connections to a cloud storage service at odd hours. The hunter wants to investigate whether this is malicious. Which hypothesis is most testable and appropriate for this scenario?
Select an answer first - 44
What should a threat hunting report include to effectively communicate findings to stakeholders?
Select an answer first - 45
A threat hunter at a financial institution is planning a hunt for data exfiltration. The organization has strict data residency requirements and uses a mix of on-premises and cloud services. The hunter has limited time and must choose between two hypotheses: (1) 'An insider is exfiltrating data via personal webmail' and (2) 'An external attacker is exfiltrating data via encrypted tunnels.' Which hypothesis should the hunter prioritize, given the organization's recent threat intelligence and the need to reduce dwell time?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.