
EC-CouncilThreat Intelligence Essentials
Domain 1Objective 1
Threat Intelligence and Essential Terminology TIE Practice Questions (Page 7)
Part of the Introduction to Threat Intelligence domain, which makes up ~14% of our current practice bank.
46questions here
10free pages
7concepts
Questions 31–35
- 31
A large organization has a mature threat intelligence program. The SOC manager needs to prioritize which indicators to block at the perimeter. The threat intelligence team has provided a list of IoCs from a recent campaign, but the SOC manager is concerned about false positives that could disrupt business operations. The team also has access to tactical intelligence that describes the adversary's preferred tools and techniques. Which approach best balances the need for immediate protection with the risk of disrupting business?
Select an answer first - 32
A threat intelligence team is struggling to get stakeholders to act on their reports. The SOC analysts say the reports are too high-level, while the executives say they are too technical. The team has been producing a single weekly report for everyone. Which change to the intelligence lifecycle would best address this problem?
Select an answer first - 33
What distinguishes threat intelligence from raw data such as a list of IP addresses?
Select an answer first - 34
Which type of threat intelligence is primarily composed of indicators of compromise (IoCs) such as IP addresses, domains, and file hashes?
Select an answer first - 35
Which type of threat intelligence is most useful for informing long-term security strategy and executive decision-making?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.