
EC-CouncilThreat Intelligence Essentials
Domain 7Objective 3
Threat Hunting Methodologies and Frameworks TIE Practice Questions (Page 1)
Part of the Threat Hunting and Detection domain, which makes up ~12% of our current practice bank.
53questions here
11free pages
20concepts
Questions 1–5
- 1
What is the primary purpose of the Lockheed Martin Cyber Kill Chain?
Select an answer first - 2
How does MITRE ATT&CK support threat hunting?
Select an answer first - 3
A threat hunting team is deciding which framework to adopt for their new hunting program. They need a framework that can help them map adversary behaviors to specific tactics and techniques, and also allow them to track the relationships between the adversary, their infrastructure, and the victims. They also want to be able to identify gaps in their detection coverage. Which combination of frameworks would best meet these needs?
Select an answer first - 4
Which phase in the Unified Kill Chain represents the adversary's actions after gaining initial access?
Select an answer first - 5
A security analyst at a mid-sized firm notices that the organization's threat intelligence feed has published a new advisory about a remote-access trojan that uses PowerShell scripts to download additional payloads from a specific set of domains. The analyst wants to proactively search the environment for signs of this activity before any alerts fire. Which approach best aligns with hypothesis-driven hunting?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.