
EC-CouncilThreat Intelligence Essentials
Domain 6Objective 3
Threat Prioritization, Actor Profiling, and Attribution TIE Practice Questions (Page 8)
Part of the Threat Intelligence Analysis domain, which makes up ~14% of our current practice bank.
42questions here
9free pages
8concepts
Questions 36–40
- 36
A regional bank's threat intelligence team receives a daily feed of 500+ indicators and alerts. The bank's core banking system is considered critical, while the marketing website is low-impact. The team must triage the feed to focus on the most relevant threats. Which approach best aligns with the bank's priorities?
Select an answer first - 37
A threat intelligence team is tracking a group that has been active for several years. Recently, the group's malware has become more sophisticated, and they have started targeting a new industry. The team has also observed a new group using similar TTPs but different malware. How should the team handle the relationship between the two groups?
Select an answer first - 38
A national infrastructure provider is assessing threats from two actors: a hacktivist group known for DDoS attacks and a state-sponsored group known for stealthy espionage. The provider's primary concern is maintaining service availability. Which actor should be prioritized?
Select an answer first - 39
An analyst is attributing a cyber incident to a known APT group. The evidence includes a malware sample that is nearly identical to the group's previous tools, but the C2 infrastructure is different and the malware contains a string that suggests a different country. The analyst must decide how to present the attribution to a government client. What is the most defensible approach?
Select an answer first - 40
Why is it important to track changes in a threat actor's behavior over time?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.