
EC-CouncilThreat Intelligence Essentials
Domain 8Objective 5
Threat Intelligence in Incident Response TIE Practice Questions (Page 10)
Part of the Sharing, Collaboration, and Incident Response domain, which makes up ~13% of our current practice bank.
53questions here
11free pages
8concepts
Questions 46–50
- 46
A security operations center (SOC) receives hundreds of alerts daily. The team is overwhelmed and frequently misses critical alerts. They have access to a commercial threat intelligence feed that provides indicators of compromise (IOCs) and adversary behavior profiles. The SOC manager wants to use this feed to reduce alert fatigue and prioritize the most important alerts. Which approach best leverages threat intelligence to achieve this goal?
Select an answer first - 47
After an incident is contained and eradicated, how can threat intelligence be used during the recovery phase?
Select an answer first - 48
During eradication, threat intelligence is used to:
Select an answer first - 49
A company's SOC is integrating a new threat intelligence platform (TIP) into its incident response workflow. The team notices that many indicators from the TIP are outdated and not relevant to their environment, leading to false positives. What is the best practice to address this challenge?
Select an answer first - 50
A security team is integrating threat intelligence into its incident response process. They have a limited budget and need to choose between purchasing a commercial threat intelligence feed or building an internal threat intelligence capability. Which approach is most effective given the constraint?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.