
EC-CouncilThreat Intelligence Essentials
Domain 8Objective 5
Threat Intelligence in Incident Response TIE Practice Questions (Page 3)
Part of the Sharing, Collaboration, and Incident Response domain, which makes up ~13% of our current practice bank.
53questions here
11free pages
8concepts
Questions 11–15
- 11
Which of the following is a common method for sharing threat intelligence with external stakeholders during an incident?
Select an answer first - 12
An organization is responding to a worm that spreads via a specific SMB vulnerability. Threat intelligence indicates that the worm has a self-propagating mechanism and can spread quickly. The incident response team needs to contain the worm, but the organization cannot afford to take all systems offline. Which containment strategy best balances the need to stop the spread with operational continuity?
Select an answer first - 13
A SOC receives an alert for a login from an IP address that is listed in a threat intelligence feed as a known proxy used by a specific APT group. However, the login is from a legitimate user and the IP is also used by a major cloud provider. The analyst must decide whether to escalate. What is the most appropriate action?
Select an answer first - 14
A company has confirmed a malware infection that uses a specific command-and-control (C2) domain. The incident response team needs to contain the threat while preserving evidence. Which containment action is most directly informed by threat intelligence?
Select an answer first - 15
During which phase of the incident response lifecycle does threat intelligence primarily help responders understand the adversary's tactics, techniques, and procedures (TTPs) to guide the investigation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.