
EC-CouncilThreat Intelligence Essentials
Domain 1Objective 5
Threat Intelligence Roles, Responsibilities, and Use Cases TIE Practice Questions (Page 4)
Part of the Introduction to Threat Intelligence domain, which makes up ~14% of our current practice bank.
33questions here
7free pages
3concepts
Questions 16–20
- 16
A threat intelligence team has identified a new malware campaign targeting the company's industry. The team has produced a detailed analysis, but the SOC and the executive team have different needs: the SOC needs technical IOCs to update detection rules, while the executives need a high-level summary of the business impact. The team must deliver the intelligence to both audiences. What is the most effective approach?
Select an answer first - 17
A company has been experiencing an increase in ransomware attacks. The security team wants to use threat intelligence to improve its incident response capabilities. The team has a threat intelligence analyst and an incident responder. Which approach best uses threat intelligence to improve incident response?
Select an answer first - 18
A security team has a threat intelligence analyst, a threat hunter, and an incident responder. The team receives a large volume of threat intelligence feeds, but the analyst is overwhelmed and cannot validate all the IOCs. The incident responder is seeing an increase in false positives because detection rules are based on unvalidated IOCs. The threat hunter is spending time validating IOCs instead of hunting. Which change best addresses the root cause of the problem?
Select an answer first - 19
In a mature threat intelligence team, which role is primarily responsible for proactively searching through networks and endpoints to discover hidden threats that may have evaded existing security controls?
Select an answer first - 20
A security team is evaluating its threat intelligence program. The team has a threat intelligence analyst, a threat hunter, and an incident responder. The analyst produces weekly reports, but the hunter and incident responder rarely use them because the reports are too long and not actionable. The CISO wants to improve the usefulness of the intelligence. Which change best addresses the issue?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.