EC-Council TIE (112-57) Certification Sample Questions

TIE Dumps, 112-57 Dumps, 112-57 PDF, TIE VCE, EC-Council 112-57 VCE, EC-Council Threat Intelligence Essentials PDFThe purpose of this Sample Question Set is to provide you with information about the EC-Council Threat Intelligence Essentials exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the 112-57 certification test. To get familiar with real exam environment, we suggest you try our Sample EC-Council TIE Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual EC-Council Threat Intelligence Essentials (TIE) certification exam.

These sample questions are simple and basic questions that represent likeness to the real EC-Council 112-57 exam questions. To assess your readiness and performance with real time scenario based questions, we suggest you prepare with our Premium EC-Council TIE Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

EC-Council 112-57 Sample Questions:

01. A security manager wants to measure how much of the SOC's detection capability comes from threat intelligence rather than from generic rules.
Which metric provides this?
a) The mean time between an incident's detection and its containment by responders
b) The share of detections that came from intelligence
c) The average number of alerts that each analyst closes per shift
d) The total number of indicators currently held in the threat intelligence platform
 
02. A SOC analyst has two alerts. Alert 1 matches an IP address whose last-seen date in the intelligence platform is two years old, with no associated campaign. Alert 2 matches a domain first seen last week in a campaign against the organization's sector, with high confidence.
Which alert should be investigated FIRST, and why?
a) Alert 2, because a recent, high-confidence, sector-relevant match is the likelier real threat
b) Alert 1, because IP addresses are more precise indicators than domains, and so produce fewer false alarms
c) Both equally, because any match against the platform is a confirmed incident
d) Alert 1, because an indicator that has persisted for two years represents a more established adversary
 
03. After containing an intrusion, responders remove the malware from the affected hosts and delete the scheduled tasks the attacker created for persistence, before any system is returned to service.
Which phase of incident response is this work?
a) Post-incident activity, reviewing how the intrusion was handled
b) Recovery, restoring the systems to normal operation
c) Containment, stopping the intrusion from spreading further
d) Eradication, removing the attacker's presence
 
04. An analyst's monthly report lists every campaign reported in the industry press, and leadership cannot tell which of them matters to the organization.
Which professional skill does the report show the analyst still needs to develop?
a) Deeper knowledge of malware internals, so each campaign's tooling and infrastructure can be described in more detail
b) Awareness of the organization's business context, so relevance and impact can be judged
c) Familiarity with more frameworks, so each campaign maps to several models
d) Faster collection, so campaigns appear in the report closer to the day they were first reported
 
05. An intelligence team briefs leadership that advances in quantum computing may eventually break the public-key cryptography protecting the organization's data, and that adversaries are already collecting encrypted data to decrypt later.
Which data should the organization prioritize for stronger protection FIRST?
a) Data that is already encrypted with current algorithms, because it will be safe until the quantum threat is confirmed
b) Data that is regenerated daily, such as log files, because it is the largest volume the organization holds
c) Sensitive data that must stay secret for years, since it will still matter when it can be decrypted
d) Public marketing material, because it is the data most often intercepted in transit
 
06. Members of a sharing group exchange indicators by email, in PDF reports, and in spreadsheets, and each recipient retypes the indicators into its own tools.
Which sharing challenge does this illustrate, and what addresses it?
a) Low-quality submissions, addressed by having each indicator reviewed before it is shared with the group
b) Lack of trust, addressed by vetting each member before it submits
c) Legal exposure, addressed by signing a sharing agreement that covers each member of the group
d) Inconsistent formats, addressed by adopting a standard machine-readable format for exchange
 
07. Six months ago a SOC began enriching every alert with threat intelligence before triage. A manager wants to know whether this has reduced the time analysts waste on alerts that turn out to be harmless.
Which measure answers the question?
a) The trend in the false-positive rate since enrichment began
b) The mean time to respond to confirmed incidents, before and after the change
c) The count of threat feeds the SOC subscribes to, before and after the change
d) The mean time to respond to confirmed incidents, before and after the change
 
08. Two companies that compete in the same market agree to share threat intelligence about attacks on their sector.
Beyond data-protection law, which legal consideration should shape what they exchange?
a) Export control law, which prohibits sharing any technical information with another company
b) Employment law, which restricts analysts from discussing their work with staff of another employer
c) Competition law, which means the exchange should stay limited to threat data and exclude commercially sensitive information
d) Contract law, which requires a purchase or licensing agreement before intelligence can change hands
 
09. Which term describes an adversary's practice of stealing encrypted data today in the expectation that future technology will allow it to be decrypted?
a) Harvest now, decrypt later
b) Advanced persistent threat (APT)
c) Ransomware-as-a-service (RaaS)
d) Living off the land
 
10. Which type of member-driven body lets organizations from different industry sectors exchange threat intelligence with one another?
a) A sector ISAC
b) An ISAO
c) A vendor's customer forum
d) A national CERT

Answers:

Question: 01
Answer: b
Question: 02
Answer: a
Question: 03
Answer: d
Question: 04
Answer: b
Question: 05
Answer: c
Question: 06
Answer: d
Question: 07
Answer: b
Question: 08
Answer: c
Question: 09
Answer: a
Question: 10
Answer: b

Note: For any error in EC-Council Threat Intelligence Essentials (TIE) (112-57) certification exam sample questions, please update us by writing an email on feedback@edusum.com.

Rating: 4.8 / 5 (124 votes)