Cyber Threat Intelligence Lifecycle Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cyber Threat Intelligence Lifecycle flashcards as text
Which phase of the CTI lifecycle is responsible for converting analyzed intelligence into a format suitable for the intended audience?
Answer: Production
The Production phase packages analyzed intelligence into finished products (reports, briefs, feeds) tailored to the specific needs and technical level of the audience.
A CTI team identifies a new ransomware group but lacks clarity on their initial access methods. Which CTI lifecycle phase should be revisited to address this gap?
Answer: Direction
Identified intelligence gaps should trigger a return to the Direction phase to redefine requirements and refocus collection efforts.
When evaluating the reliability of a CTI source, analysts often use an admiralty scale rating. What does a source rated '1' on the reliability scale indicate?
Answer: The source is completely reliable
On the admiralty scale, a reliability rating of '1' (or 'A') indicates the source has a proven track record and is considered completely reliable.
Which term describes a threat actor's consistent patterns of behavior across multiple intrusions, such as preferred tools and techniques, that remain relatively stable over time?
Answer: Tactics, Techniques, and Procedures (TTPs)
TTPs represent the behavioral fingerprint of a threat actor and are more durable intelligence than IOCs, which adversaries can change easily.
An organization shares a finished threat intelligence report with an ISAC. Which phase of the CTI lifecycle does this action represent?
Answer: Dissemination
Sharing finished intelligence products with trusted communities like ISACs is a core activity of the Dissemination phase.
Which of the following is an example of technical threat intelligence?
Answer: A malware hash list for firewall blocklisting
Technical threat intelligence includes machine-actionable artifacts like hashes, IP addresses, and domains that are directly integrated into security controls.
The Pyramid of Pain model, created by David Bianco, suggests that blocking which type of indicator causes the most pain to an adversary?
Answer: TTPs
TTPs sit at the top of the Pyramid of Pain because forcing adversaries to change their behaviors and tools requires significant effort and investment.