
EC-CouncilThreat Intelligence Essentials
Domain 1Objective 5
Threat Intelligence Roles, Responsibilities, and Use Cases TIE Practice Questions (Page 3)
Part of the Introduction to Threat Intelligence domain, which makes up ~14% of our current practice bank.
33questions here
7free pages
3concepts
Questions 11–15
- 11
A security operations center (SOC) has just received a new threat intelligence feed containing indicators of compromise (IOCs) for a ransomware family that is actively targeting the organization's sector. The SOC manager wants to ensure that the intelligence is used effectively across the team. The team consists of a threat intelligence analyst, a detection engineer, and an incident responder. Which distribution of responsibilities best ensures that the intelligence is turned into actionable protection?
Select an answer first - 12
A security team is implementing a new threat intelligence program. The team has hired a threat intelligence analyst, a threat hunter, and an incident responder. The program's goal is to improve the organization's ability to detect and respond to cyber threats. Which set of responsibilities best aligns with the roles to achieve this goal?
Select an answer first - 13
A security operations center (SOC) is reviewing its incident response process after a recent breach. The team includes a threat intelligence analyst, a threat hunter, and an incident responder. The post-incident review reveals that the team lacked visibility into the attacker's activities before the breach was detected. Which improvement best addresses this gap by leveraging the team's roles?
Select an answer first - 14
A mid-sized company has a small security team: one analyst, one incident responder, and one threat hunter. The CISO wants to improve the team's ability to detect and respond to targeted phishing campaigns. The analyst has been spending most of their time manually correlating alerts from the SIEM, leaving little time for deep-dive analysis of the latest phishing tactics. The incident responder is often pulled into false-positive investigations. The threat hunter has been focusing on host-based anomalies but has not been incorporating external threat intelligence feeds. Which change would best align the team's roles with their core responsibilities to improve detection and response?
Select an answer first - 15
A security team is planning its response to a potential advanced persistent threat (APT) that has been reported in the industry. The team includes a threat intelligence analyst, a threat hunter, and an incident responder. The CISO wants to ensure that the team is prepared to detect and respond to the APT. Which plan best uses the team's roles?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.