
EC-CouncilThreat Intelligence Essentials
Domain 7Objective 5
Threat Hunting Tool Selection and Techniques TIE Practice Questions (Page 3)
Part of the Threat Hunting and Detection domain, which makes up ~12% of our current practice bank.
40questions here
8free pages
7concepts
Questions 11–15
- 11
Which threat hunting technique is most effective for detecting previously unknown threats that do not match any known indicators?
Select an answer first - 12
A security team uses a SIEM and an EDR, but the two tools are not integrated. The team wants to enrich EDR alerts with SIEM context and automatically create hunting queries based on new IOCs. What should they do?
Select an answer first - 13
A security analyst wants to detect unknown malware that may be exfiltrating data from the network. The analyst has access to NetFlow data and can query the SIEM. Which approach is most appropriate?
Select an answer first - 14
An organization has a limited budget and needs a threat hunting tool. Which approach best aligns with budget constraints while still meeting basic hunting needs?
Select an answer first - 15
A threat hunting team needs to choose a primary technique for a new hunt. They want to detect a known APT group's tactics, but they also want to discover any unknown variants of the group's malware. Which technique should they prioritize?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.