Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 8Objective 5

Threat Intelligence in Incident Response TIE Practice Questions (Page 7)

Part of the Sharing, Collaboration, and Incident Response domain, which makes up ~13% of our current practice bank.

53questions here
11free pages
8concepts

Questions 31–35

  1. 31application · medium

    During an incident investigation, an analyst discovers a suspicious file on a compromised host. The analyst wants to determine if this file is related to a known threat actor and understand the potential impact. Which action best uses threat intelligence during the analysis phase?

    Select an answer first
  2. 32foundation · easy

    Which of the following is a best practice for applying threat intelligence in incident response?

    Select an answer first
  3. 33expert · hard

    An organization is reviewing its incident response capabilities after a major incident. The review finds that threat intelligence was used reactively, only after the incident was detected, rather than proactively. Which improvement would best address this gap?

    Select an answer first
  4. 34application · medium

    After a malware incident, the organization wants to ensure that all affected systems are clean before restoring them to production. Threat intelligence indicates that the malware has multiple variants and may have left rootkits. Which recovery validation step is most important?

    Select an answer first
  5. 35application · medium

    A company is responding to a data breach and has identified the attack vector. Which stakeholder group should receive threat intelligence during the incident?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.