← All CAP Flashcard Decks

Threat Intelligence & Analysis Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Threat Intelligence & Analysis flashcards as text
  1. Which threat intelligence sharing framework uses a structured language called STIX to represent cyber threat information?

    Answer: TAXII

    TAXII (Trusted Automated eXchange of Indicator Information) is the transport protocol used to share STIX-formatted threat intelligence.

  2. In the context of threat intelligence, what does the term 'TTPs' stand for?

    Answer: Tactics, Techniques, and Procedures

    TTPs stands for Tactics, Techniques, and Procedures — the behavioral patterns that describe how threat actors operate.

  3. A security analyst receives intelligence indicating that a known APT group is targeting organizations in your sector. At what intelligence level is this information MOST useful?

    Answer: Strategic

    Strategic intelligence informs senior leadership about threat actors targeting specific sectors, helping guide risk decisions and resource allocation.

  4. Which MITRE framework specifically maps adversary behaviors to detection and mitigation techniques for enterprise environments?

    Answer: MITRE ATT&CK

    MITRE ATT&CK (Adversarial Tactics, Techniques & Common Knowledge) is the knowledge base mapping real-world adversary behaviors to defensive countermeasures.

  5. What is the primary purpose of an Indicator of Compromise (IOC)?

    Answer: To identify evidence that a system has been breached

    IOCs are forensic artifacts — such as file hashes, IP addresses, or domain names — that indicate a system may have been compromised.

  6. Which threat intelligence source provides the MOST timely information about zero-day vulnerabilities?

    Answer: Commercial threat intelligence feeds

    Commercial threat intelligence feeds often have dedicated research teams and first-mover access to zero-day discoveries through private researcher networks.

  7. During threat modeling, which element of the PASTA methodology represents the final stage where attack simulations are performed?

    Answer: Stage VII: Risk and impact analysis

    PASTA Stage VII (Risk and Impact Analysis) synthesizes all previous stages to simulate attacks and quantify business impact, forming the basis for risk treatment decisions.