Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 6Objective 3

Threat Prioritization, Actor Profiling, and Attribution TIE Practice Questions (Page 9)

Part of the Threat Intelligence Analysis domain, which makes up ~14% of our current practice bank.

42questions here
9free pages
8concepts

Questions 41–42

  1. 41expert · hard

    A threat intelligence analyst is preparing an attribution report for a joint government-industry task force. The evidence includes a unique malware family, a C2 domain that was previously used by a known APT, and a malware sample that contains a string in a language commonly associated with another country. The analyst has high confidence in the malware family but low confidence in the C2 domain link. How should the analyst present the attribution?

    Select an answer first
  2. 42application · medium

    A security team notices that a previously observed malware family now uses a new packer and communicates with different C2 domains, but the decryption routine and the target industries remain identical. What should the team conclude about the threat actor?

    Select an answer first
Finished these 2 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to TIE

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.