
EC-CouncilThreat Intelligence Essentials
Domain 7Objective 3
Threat Hunting Methodologies and Frameworks TIE Practice Questions (Page 4)
Part of the Threat Hunting and Detection domain, which makes up ~12% of our current practice bank.
53questions here
11free pages
20concepts
Questions 16–20
- 16
A security analyst is hunting for unusual activity in a company that has a strict policy: employees are not allowed to use USB drives. The analyst notices that a specific workstation has been mounting USB devices frequently during off-hours. Which hunting approach is most directly applied here?
Select an answer first - 17
Which technique is commonly used in threat hunting to correlate events across multiple data sources?
Select an answer first - 18
A security analyst is setting up a baseline for network traffic to detect anomalies. The company has a standard 9-to-5 workday, and most employees work from the office. Which approach would be most effective for establishing a baseline?
Select an answer first - 19
A security operations center (SOC) receives an alert about a potential malware infection on a user's workstation. The on-call analyst immediately isolates the workstation and begins collecting forensic evidence. Meanwhile, a threat hunter wants to determine if the same malware has affected other workstations in the organization. Which statement correctly differentiates the threat hunter's role from the incident responder's role?
Select an answer first - 20
Why is network traffic a valuable data source for threat hunting?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.