
EC-CouncilThreat Intelligence Essentials
Domain 4Objective 1
Threat Intelligence Feeds, Sources, and Evaluation Criteria TIE Practice Questions (Page 3)
Part of the Data Collection and Sources domain, which makes up ~13% of our current practice bank.
39questions here
8free pages
3concepts
Questions 11–15
- 11
A healthcare organization is evaluating threat intelligence sources to support its incident response team. They need indicators of compromise (IOCs) that are specific to the healthcare sector and have been validated by analysts. Which source type best fits this requirement?
Select an answer first - 12
An analyst notices that a threat intelligence feed frequently reports IOCs that turn out to be false positives when checked against their environment. The feed also lags behind other sources in reporting new campaigns. Which two evaluation criteria are most clearly deficient?
Select an answer first - 13
Which statement best describes the purpose of a threat intelligence feed?
Select an answer first - 14
A threat intelligence team is reviewing a feed that provides IOCs for a specific campaign. The feed includes hashes, IPs, and domains, but lacks information about the attacker's TTPs or the campaign's objectives. The team needs to understand the threat actor's behavior to improve detection. Which evaluation criterion is most deficient in this feed?
Select an answer first - 15
A security team is considering using a free open-source feed for their threat intelligence. They are concerned about the reliability and sustainability of the feed. Which factor is most important to evaluate before relying on it?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.