← All CAP Flashcard Decks

Threat Intelligence & Analysis Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Threat Intelligence & Analysis flashcards as text
  1. Which term describes the concept that threat intelligence must be delivered in time to be actionable for decision-makers?

    Answer: Timeliness

    Timeliness is a core attribute of threat intelligence — even highly accurate intelligence has no value if it arrives after a decision window has closed.

  2. What is 'analysis of competing hypotheses' (ACH) used for in threat intelligence?

    Answer: Reducing cognitive bias by systematically evaluating multiple explanations for observed evidence

    ACH is a structured analytic technique that helps analysts evaluate multiple hypotheses against evidence to reduce cognitive bias and anchoring.

  3. In a threat intelligence program, what does 'collection management' involve?

    Answer: Directing collection resources to fill intelligence gaps and satisfy requirements

    Collection management directs intelligence collection assets and sources to fill identified gaps and answer priority intelligence requirements (PIRs).

  4. Which vulnerability scoring system is MOST commonly referenced in threat intelligence to prioritize remediation efforts?

    Answer: CVSS (Common Vulnerability Scoring System)

    CVSS provides standardized numerical scores (0-10) for vulnerability severity, widely used across the industry to prioritize patching and risk treatment.

  5. What is the primary risk of relying exclusively on open-source intelligence (OSINT) for threat analysis?

    Answer: OSINT may lack specificity and contain outdated or inaccurate information

    OSINT is publicly available and may lack specificity, timeliness, or accuracy compared to intelligence gathered through classified or proprietary means.

  6. When a threat intelligence analyst identifies a pattern suggesting an imminent attack on an organization's infrastructure, this is BEST described as which type of intelligence?

    Answer: Warning intelligence

    Warning intelligence alerts decision-makers to imminent threats requiring immediate action to prevent or mitigate an attack.

  7. Which element distinguishes threat intelligence from raw threat data?

    Answer: Threat intelligence has been analyzed and contextualized to support decision-making

    Threat intelligence is raw data that has been processed, analyzed, and contextualized to provide actionable insights for specific audiences and decisions.