โ† All CCP Flashcard Decks

Cyber Threat Intelligence Lifecycle Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cyber Threat Intelligence Lifecycle flashcards as text
  1. A CTI analyst is writing intelligence requirements for a financial services firm. Which framework is most commonly used to structure these requirements as Priority Intelligence Requirements (PIRs)?

    Answer: PIR/EEI framework

    The PIR/EEI (Priority Intelligence Requirements / Essential Elements of Information) framework structures the intelligence requirements that drive collection planning.

  2. During analysis, a CTI team uses kill chain analysis and notes adversary activity stopped at the 'Weaponization' stage. What does this imply?

    Answer: The adversary prepared a payload but did not yet deliver it

    Weaponization is the stage where the adversary creates the attack payload (e.g., embedding malware in a document) before delivering it to the target.

  3. Which attribute makes OSINT a particularly valuable collection source during the Direction and Collection phases of the CTI lifecycle?

    Answer: It is free and publicly accessible

    OSINT is valuable because it is freely and publicly available, providing broad coverage at low cost, though it still requires analysis and validation.

  4. A CTI analyst receives a report about a threat actor but cannot verify the source's credibility. Which step best reflects sound analytical tradecraft?

    Answer: Corroborate the report against additional independent sources before acting

    Sound analytical tradecraft requires corroborating intelligence from independent sources before assigning confidence levels or disseminating findings.

  5. Which CTI lifecycle phase explicitly involves mapping adversary behavior to a standardized framework like MITRE ATT&CK to produce actionable insights?

    Answer: Analysis

    The Analysis phase involves interpreting processed data, including mapping observed adversary behaviors to ATT&CK techniques for contextual understanding.

  6. An organization receives threat intelligence indicating a specific CVE is being actively exploited in the wild. Which CTI consumer would most directly act on this information?

    Answer: Vulnerability management and patch team

    Active exploitation of a CVE is directly actionable by the vulnerability management and patch team, who prioritize remediation based on threat intelligence.

  7. In the context of the CTI lifecycle, what is 'intelligence fusion'?

    Answer: Combining data from multiple sources and disciplines to produce comprehensive intelligence

    Intelligence fusion integrates data from multiple collection disciplines (OSINT, HUMINT, SIGINT) to produce a more complete and accurate intelligence picture.