
EC-CouncilThreat Intelligence Essentials
Domain 6Objective 3
Threat Prioritization, Actor Profiling, and Attribution TIE Practice Questions (Page 7)
Part of the Threat Intelligence Analysis domain, which makes up ~14% of our current practice bank.
42questions here
9free pages
8concepts
Questions 31–35
- 31
A security operations center (SOC) receives a large number of threat intelligence feeds. The SOC is responsible for protecting a hospital's patient records system, which is critical, and a public-facing appointment portal, which is less critical. The SOC has limited analysts. Which triage strategy is most effective?
Select an answer first - 32
Which term best describes the degree of certainty that an attribution conclusion is correct?
Select an answer first - 33
A financial institution uses a risk matrix to prioritize threats. The institution's transaction processing system is critical, and its employee email system is important but not critical. A vulnerability is discovered in the email system with a CVSS score of 9.0, and a separate vulnerability in the transaction system with a CVSS score of 7.5. The institution has limited patching resources. Which vulnerability should be patched first?
Select an answer first - 34
Which element is most important to include in an attribution report?
Select an answer first - 35
Which action is an example of threat intelligence triage?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.