Skip to content

Security Incident and Threat Intelligence Integrations Questions

Practice questions for Security Incident and Threat Intelligence Integrations topic in Certified Implementation Specialist - Security Incident Response. 28 questions covering this domain.

28 questions6 easy14 medium8 hard
Q1
easy

Which observable types are enriched by the Shodan integration?

Q2
hard

Before Microsoft Graph Security API alert ingestion can be configured, which product and dependency combination must be in place?

Q3
medium

An analyst wants to manually send observables from a security incident to TISC. Which path is correct?

Q4
medium

When an analyst uses Send Observable to TISC, which data is captured during the push?

Q5
medium

Which statement correctly describes WHOISIQ enrichment behavior?

Q6
hard

Your team enabled automatic push for TISC. What change should analysts expect when associating observables to a security incident?

Q7
medium

Which role performs Microsoft Graph alert profile setup and field mapping for security incidents?

Q8
easy

An analyst manually sends an observable to TISC and discovers that the observable does not yet exist there. What happens first?

Q9
medium

During a manual TISC push, an analyst selects an observable that already exists in TISC. What is the expected result?

Q10
medium

Which integration performs automatic lookups on certificate serial number observables?

Q11
easy

Where do Shodan enrichment results appear for supported observables?

Q12
medium

A team wants to manually push observable data into TISC from SIR. What prerequisite must be true for the data to be pushed?

Q13
hard

Which capability is provided by TISC Context for SIR-associated observables that are also present in TISC?

Q14
hard

During Microsoft Graph Security API setup, which task belongs to alert profile configuration rather than dashboarding or risk management?

Q15
easy

How often does Shodan check for new observables to enrich recognized types?

Q16
hard

Which prerequisite combination is required for Microsoft Graph setup?

Q17
medium

Which observable set is supported for automatic lookups by the RISKIQ SSL Certificates API?

Q18
easy

For Microsoft Graph Security API integration, what must the administrator do as part of setup?

Q19
medium

Which manual lookup can WHOISIQ perform from the Observables table?

Q20
medium

A new IP observable is added to a security incident. What should an analyst expect from Shodan?

Sign in to see all 28 questions

Create a free account to browse all questions — completely free during our launch phase.