
EC-CouncilThreat Intelligence Essentials
Domain 6Objective 3
Threat Prioritization, Actor Profiling, and Attribution TIE Practice Questions (Page 4)
Part of the Threat Intelligence Analysis domain, which makes up ~14% of our current practice bank.
42questions here
9free pages
8concepts
Questions 16–20
- 16
A hospital's security operations center receives threat intelligence from multiple sources. One feed reports a new ransomware strain targeting Windows servers, another reports a phishing campaign against a specific email gateway, and a third contains generic malware signatures. The hospital's most critical asset is the electronic health record (EHR) system, which runs on Windows servers. Which feed should the analyst escalate first?
Select an answer first - 17
A manufacturing company is conducting a threat prioritization exercise. The company has three key assets: a public web server, an internal HR database, and a proprietary product design repository. The web server is externally accessible but contains only marketing content; the HR database contains employee PII; the design repository is the company's main competitive advantage. Which asset should be considered the most critical for prioritization?
Select an answer first - 18
In a risk matrix used for threat prioritization, which two dimensions are typically plotted to determine the overall risk rating?
Select an answer first - 19
What is the primary purpose of attribution in threat intelligence?
Select an answer first - 20
Why is it important to communicate uncertainty in attribution conclusions?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.