
EC-CouncilThreat Intelligence Essentials
Domain 1Objective 4
Threat Intelligence Lifecycles and Maturity Models TIE Practice Questions (Page 3)
Part of the Introduction to Threat Intelligence domain, which makes up ~14% of our current practice bank.
41questions here
9free pages
5concepts
Questions 11–15
- 11
Why is the threat intelligence lifecycle considered iterative rather than a one-time linear process?
Select an answer first - 12
A threat intelligence team produces a weekly report for executives. After a major security incident, the executives complain that the report did not cover the threat actor involved. The team reviews the incident and realizes they had not collected data from a specific dark web forum where the actor was active. According to the threat intelligence lifecycle, what should the team do next?
Select an answer first - 13
A threat intelligence team has just delivered a report on a new exploit kit. The report was well-received, but the team noticed that the indicators were not directly useful to the SOC because they lacked context about the affected systems. What should the team do to improve the next cycle?
Select an answer first - 14
During the feedback phase of the threat intelligence lifecycle, what is the primary purpose of collecting input from intelligence consumers?
Select an answer first - 15
An organization's threat intelligence program has standardized processes for collection, analysis, and dissemination, and these processes are documented and followed across the team. However, the program does not yet use metrics to improve its performance. According to a typical maturity model, what is the next level the organization should aim for?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.