Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 8Objective 5

Threat Intelligence in Incident Response TIE Practice Questions (Page 1)

Part of the Sharing, Collaboration, and Incident Response domain, which makes up ~13% of our current practice bank.

53questions here
11free pages
8concepts

Questions 1–5

  1. 1expert · hard

    After a severe incident, the organization is planning to restore systems from backups. Threat intelligence indicates that the attacker had access to the backup system and may have tampered with backups. The incident response team must ensure that restored systems are clean. What is the most reliable recovery approach?

    Select an answer first
  2. 2foundation · easy

    Which of the following is a primary way threat intelligence enriches incident data during investigation?

    Select an answer first
  3. 3foundation · easy

    In post-incident activities, threat intelligence is primarily used to:

    Select an answer first
  4. 4application · medium

    A SOC analyst sees an alert for a suspicious outbound connection from a finance workstation. The threat intelligence feed shows that the destination IP is associated with a known phishing campaign. What should the analyst do first?

    Select an answer first
  5. 5expert · hard

    After eradicating a sophisticated threat, a company is planning recovery. The threat actor is known to use multiple persistence mechanisms and has a history of re-infection. Which recovery approach is most likely to prevent recurrence?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.