Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 2Objective 3

The Threat Intelligence Generation Process TIE Practice Questions (Page 5)

Part of the Types of Threat Intelligence domain, which makes up ~11% of our current practice bank.

42questions here
9free pages
6concepts

Questions 21–25

  1. 21application · medium

    A security operations center (SOC) analyst is tasked with building a threat intelligence feed for a financial institution. The analyst has access to internal firewall logs, DNS query logs, and a commercial threat feed. The analyst notices that the commercial feed contains IP addresses in a format that differs from the internal logs, and many entries are duplicates. Which sequence of actions best aligns with the threat intelligence generation process?

    Select an answer first
  2. 22foundation · easy

    What is the primary purpose of correlation in the analysis stage of threat intelligence generation?

    Select an answer first
  3. 23expert · hard

    An analyst is investigating a series of alerts involving a legitimate cloud storage service being used to host malware. The malware is downloaded by several employees, but the domain is widely used for legitimate business purposes. The analyst must produce intelligence that reduces risk without disrupting business operations. What is the most appropriate action?

    Select an answer first
  4. 24expert · hard

    A threat intelligence team has identified a new vulnerability in a widely used software product. The team needs to inform their organization's IT team, executives, and possibly external partners. The vulnerability is not yet publicly disclosed, and the team wants to avoid causing panic. What is the most appropriate dissemination strategy?

    Select an answer first
  5. 25expert · hard

    A security team is ingesting threat data from multiple sources. They notice that the same IP address is reported as malicious by one source and benign by another. The team needs to decide how to handle this conflict before the data is used in detection rules. What is the best approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.