Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 2Objective 1

Understanding the Different Types of Threat Intelligence TIE Practice Questions (Page 2)

Part of the Types of Threat Intelligence domain, which makes up ~11% of our current practice bank.

21questions here
5free pages
5concepts

Questions 6–10

  1. 6application · medium

    An organization is evaluating its threat intelligence needs. The security operations team needs timely information about active campaigns to improve detection, while the executive team needs a broader understanding of the threat landscape for risk management. Which approach best addresses both needs?

    Select an answer first
  2. 7expert · hard

    A security operations team is overwhelmed by alerts from their SIEM. They receive a threat intelligence feed with a high volume of indicators, but many are false positives. The team wants to reduce noise and focus on the most relevant threats. They decide to prioritize intelligence that describes the behavior of attackers, such as the use of specific tools and techniques, rather than just blocking individual indicators. Which type of threat intelligence should they incorporate into their detection strategy?

    Select an answer first
  3. 8expert · hard

    A large enterprise is building a threat intelligence program. The CISO wants to understand the organization's exposure to nation-state actors for board reporting. The SOC needs actionable indicators to block known malicious infrastructure. The security architecture team needs to understand the TTPs of relevant threat actors to improve detection. The incident response team needs to track ongoing campaigns that may affect the organization. Which combination of threat intelligence types best addresses all these needs?

    Select an answer first
  4. 9application · medium

    A security analyst at a mid-sized company needs to block an active malware campaign that is using known command-and-control domains and specific file hashes. The analyst has access to a threat intelligence platform that provides feeds of domains, IPs, and file hashes. Which type of threat intelligence should the analyst use to update the firewall and endpoint detection rules immediately?

    Select an answer first
  5. 10expert · hard

    A company is responding to a ransomware attack. The incident response team has identified the ransomware family and the likely entry vector. The CEO wants a brief update on the potential business impact, while the technical team needs to know the specific actions to contain the spread. Which combination of threat intelligence types should be used?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.