
EC-CouncilThreat Intelligence Essentials
Domain 7Objective 5
Threat Hunting Tool Selection and Techniques TIE Practice Questions (Page 8)
Part of the Threat Hunting and Detection domain, which makes up ~12% of our current practice bank.
40questions here
8free pages
7concepts
Questions 36–40
- 36
A security team has a limited budget and needs to hunt for indicators from a recent threat report. They have a SIEM that stores logs for 30 days, an EDR with 90 days of endpoint data, and no TIP. The report contains file hashes, domains, and IP addresses. Which approach is most effective within the constraints?
Select an answer first - 37
An organization received a threat intelligence report containing a list of malicious file hashes, domains, and IP addresses. The security team wants to search their environment for any matches. Which approach is most efficient?
Select an answer first - 38
Which threat hunting technique involves starting with a specific theory about how an attacker might operate and then searching for evidence to confirm or refute that theory?
Select an answer first - 39
A company with a mature security program wants to add threat hunting capabilities. They already have a SIEM that collects logs from all critical systems and an EDR on all endpoints. They need to prioritize hunting for advanced persistent threats that may have evaded existing defenses. Which tool addition would be most valuable?
Select an answer first - 40
A security analyst hypothesizes that an attacker is using PowerShell to execute malicious scripts on workstations. The analyst wants to test this hypothesis using available tools. Which combination of tools and data sources would best support this investigation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to TIE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.