Threat Intelligence & Analysis Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Threat Intelligence & Analysis flashcards as text
A threat intelligence analyst is evaluating a report claiming a nation-state actor is using a specific malware family. Which factor MOST determines the credibility of this intelligence?
Answer: The reputation and track record of the source
Source credibility — based on historical accuracy, methodology, and independence — is the primary factor in evaluating the reliability of threat intelligence.
What is 'threat hunting' in the context of a cybersecurity program?
Answer: Proactive search for hidden threats that evade automated detection
Threat hunting is a proactive, human-led process of iteratively searching through networks and systems to detect threats that automated tools have not flagged.
Which kill chain phase involves the adversary researching and identifying targets before an attack?
Answer: Reconnaissance
Reconnaissance is the first phase of the Lockheed Martin Cyber Kill Chain, where attackers gather information about their intended target.
In threat intelligence, what does 'pivoting' refer to?
Answer: Using one indicator to discover related indicators and infrastructure
Pivoting is the analytical technique of using a known IOC (such as a domain or IP) to discover additional related infrastructure and indicators used by the same threat actor.
Which type of threat actor is typically characterized by advanced capabilities, long dwell times, and nation-state sponsorship?
Answer: Advanced Persistent Threats (APTs)
APTs are sophisticated, well-funded threat actors — typically nation-state affiliated — that conduct long-term, targeted intrusion campaigns with persistence and stealth.
What is the Diamond Model of Intrusion Analysis primarily used for?
Answer: Structuring the analysis of adversary, capability, infrastructure, and victim relationships
The Diamond Model provides a framework for structuring intrusion analysis around four core features: adversary, capability, infrastructure, and victim.
A CAP practitioner is reviewing threat intelligence to update a system's risk assessment. Which intelligence product would BEST support this activity?
Answer: A finished intelligence report with context and analysis
Finished intelligence reports provide analyzed, contextualized information suitable for risk assessment decisions, unlike raw data that requires further analysis.