
EC-CouncilThreat Intelligence Essentials
Domain 6Objective 3
Threat Prioritization, Actor Profiling, and Attribution TIE Practice Questions (Page 3)
Part of the Threat Intelligence Analysis domain, which makes up ~14% of our current practice bank.
42questions here
9free pages
8concepts
Questions 11–15
- 11
A cybersecurity team is using a risk matrix to prioritize threats for a hospital. The hospital has a patient monitoring system (IoT devices), an EHR system, and a public website. A threat report indicates a new ransomware that targets IoT devices, but the exploit requires being on the same network. Another report describes a phishing campaign that targets hospital staff and can lead to credential theft. Which threat should be prioritized?
Select an answer first - 12
What is the purpose of grouping related activities into actor campaigns?
Select an answer first - 13
In actor profiling, what does 'capability' refer to?
Select an answer first - 14
A large e-commerce company uses a risk matrix to prioritize threats. The company's customer database is critical, and its public website is important but not critical. A vulnerability is discovered in the website's content management system with a CVSS score of 9.8, and a separate vulnerability in the customer database with a CVSS score of 6.5. The company has limited patching resources. Which vulnerability should be patched first?
Select an answer first - 15
A regional bank's threat intelligence team receives a daily feed containing hundreds of raw indicators. The bank's core banking system is a legacy mainframe that cannot be patched, while the public-facing mobile app is fully patched and containerized. The team must prioritize which indicators to investigate first. Using a risk-matrix approach, which factor should carry the most weight when ranking the indicators?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.