Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 6Objective 3

Threat Prioritization, Actor Profiling, and Attribution TIE Practice Questions (Page 1)

Part of the Threat Intelligence Analysis domain, which makes up ~14% of our current practice bank.

42questions here
9free pages
8concepts

Questions 1–5

  1. 1expert · hard

    An analyst must write an attribution report for a board of directors. The report will be used to decide whether to invest in additional security controls. The evidence is strong but not conclusive. Which approach best supports the board's decision-making?

    Select an answer first
  2. 2expert · hard

    A security team is investigating a series of attacks on a media organization. The attacks include website defacement, email phishing, and a sophisticated intrusion that exfiltrated unpublished articles. The defacement used a known hacktivist tool, the phishing emails were sent from a compromised account, and the intrusion used a zero-day exploit. How should the team profile the actors?

    Select an answer first
  3. 3application · medium

    A threat intelligence analyst must write a report on a suspected state-sponsored intrusion for the company's board of directors. The evidence is strong but not conclusive. What is the most appropriate way to present the findings?

    Select an answer first
  4. 4application · medium

    An incident response team observes a series of intrusions at a defense contractor. The attacks use a custom backdoor that shares code with a known APT group's tool, but the command-and-control infrastructure is registered through a service commonly used by a different, unrelated group. The team must decide how to attribute the incident. What is the most appropriate conclusion?

    Select an answer first
  5. 5application · medium

    An analyst has completed an attribution analysis and must write a report for a non-technical executive audience. The evidence includes overlapping infrastructure and similar malware, but the analyst is not fully certain. What is the most appropriate way to structure the report?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.