Threat Intelligence & Analysis Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Threat Intelligence & Analysis flashcards as text
Which cyber threat intelligence (CTI) maturity model indicator suggests an organization at the highest maturity level?
Answer: The organization shares intelligence with peers and contributes to community platforms
At the highest CTI maturity levels, organizations both consume and actively contribute intelligence, participating in bidirectional sharing with sector partners and ISACs.
A threat actor uses legitimate cloud services as command-and-control (C2) infrastructure. Which threat intelligence technique is BEST suited to detect this behavior?
Answer: Behavioral analysis and anomaly detection
Behavioral analysis and anomaly detection can identify malicious use of legitimate services by focusing on unusual patterns rather than known-bad indicators that attackers deliberately avoid.
Under the NIST Risk Management Framework, threat intelligence MOST directly supports which step?
Answer: Step 4: Assess
Threat intelligence directly supports the Assess step by providing current threat data to evaluate whether implemented controls effectively address real-world risks.
What is the purpose of 'threat profiling' in a CAP context?
Answer: Documenting detailed characteristics of threat actors most likely to target a system
Threat profiling documents the motivations, capabilities, and TTPs of threat actors most likely to target a specific system, informing tailored risk assessments.
Which practice helps prevent 'mind-set' bias where analysts unconsciously seek information confirming their existing conclusions?
Answer: Applying structured analytic techniques such as devil's advocacy
Structured analytic techniques like devil's advocacy, red teaming, and ACH explicitly challenge prevailing conclusions to counteract confirmation bias.
In the intelligence cycle, which phase involves converting raw information into a finished product ready for dissemination?
Answer: Processing and Analysis
Processing and Analysis transforms raw collected data — through correlation, evaluation, and interpretation — into finished intelligence products.
Which attribute of threat intelligence ensures that the information is relevant to the specific organization receiving it?
Answer: Specificity
Specificity ensures that threat intelligence is applicable to the organization's environment, industry, and risk profile rather than generic information about all threats.