โ† All CySA+ Test Flashcard Decks

Threat Intelligence Flashcards

7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Threat Intelligence flashcards as text
  1. Which threat intelligence sharing standard uses a JSON-based format to represent cyber threat information as objects and relationships?

    Answer: STIX

    STIX (Structured Threat Information eXpression) is a JSON-based language for representing CTI objects and their relationships.

  2. A security analyst receives a threat report indicating that an APT group uses 'living off the land' techniques. What does this mean?

    Answer: The group uses legitimate system tools to avoid detection

    Living off the land (LotL) refers to attackers using built-in OS tools like PowerShell or WMI to conduct malicious activity, blending in with normal operations.

  3. Which MITRE ATT&CK tactic describes an adversary's attempts to steal credentials to gain access to systems?

    Answer: Credential Access

    Credential Access is the ATT&CK tactic covering techniques like keylogging, credential dumping, and brute forcing to obtain account credentials.

  4. What is the primary purpose of a threat intelligence platform (TIP)?

    Answer: To aggregate, correlate, and manage threat intelligence from multiple sources

    A TIP centralizes threat data from multiple feeds, enabling analysts to correlate, enrich, and act on intelligence efficiently.

  5. An analyst observes that attackers are using domain generation algorithms (DGAs). What is the main defensive value of identifying DGA patterns?

    Answer: It enables sinkholing or preemptive blocking of generated domains

    Identifying DGA patterns allows defenders to predict, sinkhole, or block generated domains before malware establishes C2 communications.

  6. Which type of threat intelligence focuses on the day-to-day activities of security operations and includes IOCs, malware hashes, and IP blocklists?

    Answer: Technical intelligence

    Technical intelligence provides specific IOCs such as hashes, IPs, and domains used directly in detection tools and blocklists.

  7. A threat analyst is mapping an adversary campaign to the Diamond Model. Which four features are core to this model?

    Answer: Actor, capability, infrastructure, victim

    The Diamond Model of intrusion analysis consists of four core features: adversary, capability, infrastructure, and victim.