
EC-CouncilThreat Intelligence Essentials
Domain 6Objective 3
Threat Prioritization, Actor Profiling, and Attribution TIE Practice Questions (Page 6)
Part of the Threat Intelligence Analysis domain, which makes up ~14% of our current practice bank.
42questions here
9free pages
8concepts
Questions 26–30
- 26
An incident response team discovers that a breach used a phishing email with a malicious attachment that matches a known APT's toolset. However, the phishing email was sent from a compromised legitimate account, and the malware's C2 infrastructure is shared with another unrelated group. What is the most appropriate attribution statement?
Select an answer first - 27
Which approach best reflects the purpose of an asset criticality assessment in threat intelligence?
Select an answer first - 28
A security analyst is preparing an attribution report for a cyber incident. The evidence includes a unique malware hash, a known command-and-control domain, and a similar phishing lure used by a specific group. However, the malware was also seen in a public sandbox analysis that could have been uploaded by anyone. What is the most appropriate way to present the attribution confidence?
Select an answer first - 29
A threat intelligence team has been tracking a financially motivated actor for two years. Over the past six months, the actor has shifted from using commodity ransomware to a custom loader and has started targeting a new industry. The team must update its tracking. What is the most appropriate action?
Select an answer first - 30
A utility company is assessing threats to its industrial control systems (ICS). A hacktivist group has threatened to disrupt operations, while a financially motivated cybercrime group has been observed scanning for internet-exposed ICS devices. The company must prioritize its defenses. Which factor is most important to consider?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.