Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 4Objective 1

Threat Intelligence Feeds, Sources, and Evaluation Criteria TIE Practice Questions (Page 5)

Part of the Data Collection and Sources domain, which makes up ~13% of our current practice bank.

39questions here
8free pages
3concepts

Questions 21–25

  1. 21application · medium

    A threat intelligence analyst is comparing two feeds. Feed A provides IOCs within minutes of a new campaign, but lacks context about the attacker. Feed B provides detailed reports but only after the campaign has been active for weeks. The analyst needs to block IOCs quickly. Which feed should be prioritized for immediate blocking decisions?

    Select an answer first
  2. 22application · medium

    A multinational corporation needs threat intelligence that covers multiple regions and languages. They want to supplement their commercial feed with additional sources that provide local context. Which source type would best provide this local perspective?

    Select an answer first
  3. 23expert · hard

    A security operations center (SOC) is considering adding a new threat intelligence source. The source is a dark web monitoring service that provides early warnings about data breaches and stolen credentials. The SOC already has a commercial feed that provides IOCs but lacks this type of early warning. The SOC has a limited budget and must justify the cost. What is the strongest justification for adding the dark web monitoring service?

    Select an answer first
  4. 24expert · hard

    A security team is evaluating a threat intelligence feed that has excellent timeliness and relevance but has a known issue: some indicators are not fully validated and occasionally point to legitimate services. The team plans to use the feed for automated blocking in their firewall. What is the most important consideration before enabling automated blocking?

    Select an answer first
  5. 25application · medium

    A security analyst is evaluating two threat intelligence feeds for integration into their SIEM. Feed X provides a high volume of indicators with a 24-hour delay, while Feed Y provides fewer indicators but updates every 10 minutes. The analyst needs to detect fast-spreading ransomware campaigns in near real-time. Which feed should the analyst prioritize, and why?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.