← All CAP Flashcard Decks

Threat Intelligence & Analysis Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Threat Intelligence & Analysis flashcards as text
  1. Which cyber threat intelligence (CTI) maturity model indicator suggests an organization at the highest maturity level?

    Answer: The organization shares intelligence with peers and contributes to community platforms

    At the highest CTI maturity levels, organizations both consume and actively contribute intelligence, participating in bidirectional sharing with sector partners and ISACs.

  2. A threat actor uses legitimate cloud services as command-and-control (C2) infrastructure. Which threat intelligence technique is BEST suited to detect this behavior?

    Answer: Behavioral analysis and anomaly detection

    Behavioral analysis and anomaly detection can identify malicious use of legitimate services by focusing on unusual patterns rather than known-bad indicators that attackers deliberately avoid.

  3. Under the NIST Risk Management Framework, threat intelligence MOST directly supports which step?

    Answer: Step 4: Assess

    Threat intelligence directly supports the Assess step by providing current threat data to evaluate whether implemented controls effectively address real-world risks.

  4. What is the purpose of 'threat profiling' in a CAP context?

    Answer: Documenting detailed characteristics of threat actors most likely to target a system

    Threat profiling documents the motivations, capabilities, and TTPs of threat actors most likely to target a specific system, informing tailored risk assessments.

  5. Which practice helps prevent 'mind-set' bias where analysts unconsciously seek information confirming their existing conclusions?

    Answer: Applying structured analytic techniques such as devil's advocacy

    Structured analytic techniques like devil's advocacy, red teaming, and ACH explicitly challenge prevailing conclusions to counteract confirmation bias.

  6. In the intelligence cycle, which phase involves converting raw information into a finished product ready for dissemination?

    Answer: Processing and Analysis

    Processing and Analysis transforms raw collected data — through correlation, evaluation, and interpretation — into finished intelligence products.

  7. Which attribute of threat intelligence ensures that the information is relevant to the specific organization receiving it?

    Answer: Specificity

    Specificity ensures that threat intelligence is applicable to the organization's environment, industry, and risk profile rather than generic information about all threats.

Threat Intelligence & Analysis Flashcards — CAP Study Cards with Answers