Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 2Objective 3

The Threat Intelligence Generation Process TIE Practice Questions (Page 7)

Part of the Types of Threat Intelligence domain, which makes up ~11% of our current practice bank.

42questions here
9free pages
6concepts

Questions 31–35

  1. 31foundation · easy

    Which of the following is a common source of raw data for threat intelligence collection?

    Select an answer first
  2. 32foundation · easy

    Which technique is commonly used during the analysis and correlation stage to identify relationships between raw data points?

    Select an answer first
  3. 33foundation · easy

    Which activity is part of the data processing and normalization stage of threat intelligence generation?

    Select an answer first
  4. 34expert · hard

    An analyst is investigating a series of intrusions that appear to be linked. Each intrusion used a different malware family, but the C2 infrastructure shares a common pattern: domains registered with the same registrar, using similar naming conventions, and hosted on the same hosting provider. The analyst wants to determine if these intrusions are part of a single campaign. What is the best analytical approach?

    Select an answer first
  5. 35expert · hard

    A threat intelligence analyst is correlating data from a dark web forum, a sandbox analysis of a new malware sample, and internal network logs. The dark web post mentions a new exploit kit, the sandbox report shows the malware using a specific domain for C2, and the internal logs show a host communicating with that domain. The analyst has limited time and must decide what to report to the SOC. What is the most appropriate action?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.