
EC-CouncilThreat Intelligence Essentials
Domain 1Objective 1
Threat Intelligence and Essential Terminology TIE Practice Questions (Page 4)
Part of the Introduction to Threat Intelligence domain, which makes up ~14% of our current practice bank.
46questions here
10free pages
7concepts
Questions 16–20
- 16
A threat intelligence team is building a new capability. They have identified a need to collect data from internal logs, open-source feeds, and commercial subscriptions. Before they start collecting, they want to ensure that the collected data will be relevant to the organization's specific risks and that the final product will be used by the incident response team. According to the threat intelligence lifecycle, which stage should they focus on first?
Select an answer first - 17
Which term refers to the behaviors, tools, and procedures that a threat actor uses to conduct an attack?
Select an answer first - 18
Which role is most likely to use tactical threat intelligence to improve security controls and detection rules?
Select an answer first - 19
A security analyst receives a daily feed of IP addresses and domain names that were observed in recent malware campaigns. The analyst wants to use this feed to prioritize which alerts to investigate. Which statement best describes the nature of this feed and its appropriate use?
Select an answer first - 20
A threat intelligence team is preparing a briefing for the chief information security officer (CISO) about the top cyber threats facing the organization over the next year. The briefing should include the potential business impact and recommended investments. Which type of threat intelligence is most appropriate for this briefing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.