
EC-CouncilThreat Intelligence Essentials
Domain 1Objective 5
Threat Intelligence Roles, Responsibilities, and Use Cases TIE Practice Questions (Page 2)
Part of the Introduction to Threat Intelligence domain, which makes up ~14% of our current practice bank.
33questions here
7free pages
3concepts
Questions 6–10
- 6
A company has a limited security budget and must choose between investing in threat intelligence capabilities to improve detection and investing in additional endpoint protection tools. The threat intelligence team argues that intelligence can improve the effectiveness of existing tools, while the endpoint team argues that more tools are needed. Which approach is most likely to provide the best return on investment?
Select an answer first - 7
A large organization has a mature security team with separate roles: a threat intelligence analyst, a threat hunter, and an incident responder. A new advanced persistent threat (APT) group has been observed targeting the organization's industry. The threat intelligence analyst has produced a detailed report on the APT's tactics, techniques, and procedures (TTPs). The CISO wants to ensure that the organization is prepared to detect and respond to this APT. Which combination of actions best leverages the team's roles?
Select an answer first - 8
A large organization has a mature SOC but is seeing an increase in stealthy attacks that bypass existing detection rules. The SOC manager wants to add a role that will proactively search for these threats, but the budget is limited and the SOC is already understaffed. The manager must choose between hiring a dedicated threat hunter or training existing analysts to perform hunting duties part-time. Which approach best balances the need for proactive hunting with the constraint of limited resources?
Select an answer first - 9
A threat intelligence team is responsible for the full intelligence lifecycle. They have collected a large amount of raw data from multiple sources, but the SOC is complaining that the intelligence they receive is often irrelevant and arrives too late to be useful. The team lead wants to improve the process. Which change should the team make to address both the relevance and timeliness issues?
Select an answer first - 10
A company's risk management team is evaluating whether to invest in additional endpoint detection and response (EDR) tools. They ask the threat intelligence team to provide information about the likelihood of a specific threat actor targeting the company and the potential impact of such an attack. Which use case of threat intelligence is being applied?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.