Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 8Objective 5

Threat Intelligence in Incident Response TIE Practice Questions (Page 5)

Part of the Sharing, Collaboration, and Incident Response domain, which makes up ~13% of our current practice bank.

53questions here
11free pages
8concepts

Questions 21–25

  1. 21application · medium

    After a security incident, the incident response team is planning recovery actions. Threat intelligence reports indicate that the attacker used a previously unknown backdoor that is now publicly documented. Which recovery step should the team prioritize to ensure the backdoor is fully removed and the system is safe to restore?

    Select an answer first
  2. 22application · medium

    A company wants to incorporate threat intelligence into its detection capabilities. They have a SIEM and want to detect known malicious IP addresses. Which method is most effective?

    Select an answer first
  3. 23application · medium

    A security team is integrating threat intelligence into its incident response process but is overwhelmed by the volume of indicators from multiple feeds. What is the best practice to address this challenge?

    Select an answer first
  4. 24foundation · easy

    Which of the following best describes how threat intelligence supports incident triage?

    Select an answer first
  5. 25application · medium

    A company has identified that a specific threat actor is using a particular set of tools and techniques. The incident response team is planning containment. Which strategy is most informed by threat intelligence?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.