
EC-CouncilThreat Intelligence Essentials
Domain 8Objective 5
Threat Intelligence in Incident Response TIE Practice Questions (Page 8)
Part of the Sharing, Collaboration, and Incident Response domain, which makes up ~13% of our current practice bank.
53questions here
11free pages
8concepts
Questions 36–40
- 36
An organization is designing its incident response plan and wants to integrate threat intelligence across all phases. Which approach best ensures that threat intelligence is effectively used throughout the incident response lifecycle?
Select an answer first - 37
An analyst receives an alert for a suspicious outbound connection to an IP address that is listed in a threat intelligence feed as a known command-and-control (C2) server. How should the analyst use this intelligence in triage?
Select an answer first - 38
An organization wants to improve its incident detection capabilities by incorporating threat intelligence into its SIEM. The security team has access to a feed of malicious IP addresses and domains. Which integration method would be most effective for using this intelligence in detection?
Select an answer first - 39
Which method is commonly used to integrate threat intelligence into detection activities?
Select an answer first - 40
An organization has confirmed a ransomware infection that is spreading laterally. Threat intelligence indicates that the ransomware uses a specific set of command-and-control (C2) domains and exploits a known vulnerability in a legacy service. The incident response team needs to contain the outbreak quickly. Which containment strategy best leverages the available threat intelligence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.