Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilThreat Intelligence Essentials

Domain 1Objective 6

Using Standards and Frameworks to Measure Effectiveness TIE Practice Questions (Page 1)

Part of the Introduction to Threat Intelligence domain, which makes up ~14% of our current practice bank.

38questions here
8free pages
3concepts

Questions 1–5

  1. 1application · medium

    An organization wants to automate the exchange of threat intelligence with a trusted community. They need a protocol that supports push and pull models for sharing STIX data. Which protocol should they use?

    Select an answer first
  2. 2foundation · easy

    When structuring a threat intelligence report to describe an adversary's behavior, which framework would be most appropriate to map the specific techniques used during an attack?

    Select an answer first
  3. 3application · medium

    A security analyst is investigating an incident where an attacker used a known vulnerability in a web application to gain initial access, then escalated privileges using a misconfigured service account, and finally established persistence by creating a new user. The analyst wants to document this in a way that aligns with a standardized framework and can be used to identify similar future attacks. Which approach is most effective?

    Select an answer first
  4. 4expert · hard

    A security operations center (SOC) has implemented MITRE ATT&CK to map their detections. They have also integrated a threat intelligence feed that provides STIX data. The SOC wants to measure the effectiveness of their detections by tracking how many ATT&CK techniques are covered by their intelligence. However, they are concerned that the intelligence feed may not be aligned with their environment. Which approach would best measure the effectiveness of the intelligence in terms of ATT&CK coverage?

    Select an answer first
  5. 5expert · hard

    A threat intelligence team is using the Cyber Kill Chain to analyze intrusions. They want to measure the effectiveness of their detection controls at each phase. They have data on the number of intrusions that were detected at each phase. Which metric would best help them identify the weakest phase in their detection?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “TIE” is a trademark of its owner, used for identification only.