Threat Intelligence Flashcards
7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Threat Intelligence flashcards as text
Which threat intelligence sharing standard uses a JSON-based format to represent cyber threat information as objects and relationships?
Answer: STIX
STIX (Structured Threat Information eXpression) is a JSON-based language for representing CTI objects and their relationships.
A security analyst receives a threat report indicating that an APT group uses 'living off the land' techniques. What does this mean?
Answer: The group uses legitimate system tools to avoid detection
Living off the land (LotL) refers to attackers using built-in OS tools like PowerShell or WMI to conduct malicious activity, blending in with normal operations.
Which MITRE ATT&CK tactic describes an adversary's attempts to steal credentials to gain access to systems?
Answer: Credential Access
Credential Access is the ATT&CK tactic covering techniques like keylogging, credential dumping, and brute forcing to obtain account credentials.
What is the primary purpose of a threat intelligence platform (TIP)?
Answer: To aggregate, correlate, and manage threat intelligence from multiple sources
A TIP centralizes threat data from multiple feeds, enabling analysts to correlate, enrich, and act on intelligence efficiently.
An analyst observes that attackers are using domain generation algorithms (DGAs). What is the main defensive value of identifying DGA patterns?
Answer: It enables sinkholing or preemptive blocking of generated domains
Identifying DGA patterns allows defenders to predict, sinkhole, or block generated domains before malware establishes C2 communications.
Which type of threat intelligence focuses on the day-to-day activities of security operations and includes IOCs, malware hashes, and IP blocklists?
Answer: Technical intelligence
Technical intelligence provides specific IOCs such as hashes, IPs, and domains used directly in detection tools and blocklists.
A threat analyst is mapping an adversary campaign to the Diamond Model. Which four features are core to this model?
Answer: Actor, capability, infrastructure, victim
The Diamond Model of intrusion analysis consists of four core features: adversary, capability, infrastructure, and victim.