Courseiva

CCNA Requirements Planning Direction And Review Questions

24 questions · Requirements Planning Direction And Review · All types, answers revealed

1
MCQmedium

An intelligence analyst is drafting the Request for Information (RFI) workflow during the direction phase. An operational team submits an RFI regarding a newly observed malware strain. What is the correct next step in the RFI management lifecycle?

A.Immediately publish the raw telemetry to the corporate intranet without validation
B.Archive the RFI immediately as operational queries fall outside the scope of CTI
C.Triage, validate, and prioritize the RFI against established intelligence priorities
D.Initiate an immediate red-team attack campaign against the external supplier
AnswerC

Validation and prioritization ensure that analytical resources are focused on high-value, relevant requests.

Why this answer

Once an RFI is submitted, it must be triaged, validated, and prioritized against existing intelligence requirements before collection and analysis tasks are assigned.

2
MCQmedium

A CTI program is conducting a formal review of its intelligence requirements to ensure alignment with changing business goals. Which phase of the intelligence cycle directly feeds into the direction and planning phase during this review?

A.Processing and Exploitation
B.Automated Malware Sandboxing
C.Dissemination and Feedback
D.Tactical Log Ingestion
AnswerC

Feedback from consumers on previous intelligence products directly informs the direction and planning phase to update requirements.

Why this answer

Feedback and review from completed intelligence operations and stakeholder evaluations provide the necessary insights to refine and adjust requirements in the direction and planning phase.

3
MCQeasy

An organization is updating its threat landscape analysis methodology to better account for sector-specific threats. Which stakeholder group should the CTI team primarily consult to gather accurate sector-specific threat requirements?

A.Social media marketing agencies
B.Commercial real estate brokers
C.Consumer product retail vendors
D.Industry-specific ISACs and regulatory compliance bodies
AnswerD

ISACs and regulatory bodies offer tailored threat intelligence sharing, sector benchmarks, and specific threat vectors.

Why this answer

Information Sharing and Analysis Centers (ISACs) or Information Sharing and Analysis Organizations (ISAOs) provide sector-specific threat intelligence and peer collaboration crucial for accurate threat requirements.

4
MCQeasy

An organization is structuring a new Threat Intelligence (TI) team and needs to ensure that strategic intelligence reaches executive leadership effectively. Which team role is primarily responsible for translating high-level threat trends into business risk assessments for board members?

A.Strategic Threat Intelligence Analyst
B.Vulnerability Assessor
C.Malware Reverse Engineer
D.Incident Responder
AnswerA

Strategic analysts specialize in communicating high-level threat trends, geopolitical events, and business risk to executive leadership.

Why this answer

The Threat Intelligence Manager or Strategic Threat Analyst bridges the gap between technical threat indicators and business risk, ensuring executive leadership understands the strategic impact.

5
Multi-Selecteasy

When establishing a Threat Intelligence program, a manager must outline the core functions of the TI team. Which TWO of the following responsibilities typically fall under a dedicated CTI team's scope? (Choose TWO)

Select 2 answers
A.Performing physical security audits of corporate parking garages
B.Writing and deploying custom business logic for customer-facing web applications
C.Analyzing threat actor campaigns, motivations, and Tactics, Techniques, and Procedures (TTPs)
D.Producing intelligence reports and briefings tailored for operational and strategic stakeholders
E.Directly configuring enterprise firewall access control lists and routing tables
AnswersC, D

Analyzing campaigns, motivations, and TTPs is a core function of a threat intelligence team.

Why this answer

CTI teams are responsible for analyzing threat actor TTPs and providing actionable intelligence to defenders. They do not typically manage network firewalls or perform software development.

6
Multi-Selectmedium

During the requirements planning phase, a CTI analyst categorizes intelligence needs based on consumer levels. Which THREE types of intelligence consumers must be addressed in a comprehensive intelligence plan? (Choose THREE)

Select 3 answers
A.Tactical level (SIEM systems, Automated security controls, SOC analysts)
B.Strategic level (Executive leadership, Board of Directors)
C.Corporate real estate leasing committees
D.Operational level (Security Operations Center managers, Incident Responders)
E.External consumer product marketing teams
AnswersA, B, D

Tactical consumers require indicators of compromise, file hashes, and IP blocklists.

Why this answer

Intelligence plans address strategic (executive), operational (managerial/defense), and tactical (technical/SOC) consumers.

7
MCQmedium

During the Requirements Planning phase of the intelligence cycle, a CTI analyst uses the Priority Intelligence Requirements (PIR) framework. What is the primary purpose of defining PIRs at this stage?

A.To schedule routine penetration testing intervals across the enterprise network
B.To outline the budget allocation for commercial threat feed subscriptions
C.To establish automated firewall blocklists for known malicious IP addresses
D.To define specific information needs that support organizational decision-making and risk reduction
AnswerD

PIRs articulate the exact gaps in knowledge that leadership needs filled to make informed security decisions.

Why this answer

PIRs focus the entire threat intelligence collection and analysis effort on answering specific, critical questions that drive decision-making for leadership.

8
Multi-Selectmedium

When planning a Threat Intelligence program budget, an organization must account for various resource categories. Which THREE resource categories should be included in the CTI program budget plan? (Choose THREE)

Select 3 answers
A.Analyst professional development, training, and industry certifications
B.Fleet vehicle insurance policies for corporate delivery trucks
C.Threat intelligence sharing memberships (e.g., ISACs, ISAOs)
D.Commercial cafeteria food and beverage restocking contracts
E.Commercial threat intelligence feed subscriptions and Threat Intelligence Platforms (TIP)
AnswersA, C, E

Training and certifications for analysts are essential personnel budget items to maintain analytical capability.

Why this answer

Budget planning for CTI must account for commercial tool subscriptions, personnel training/certifications, and intelligence platform licenses.

9
MCQmedium

An organization is establishing metrics for its Threat Intelligence program review. The CTI director wants to measure 'Collection Efficiency.' Which formula or evaluation method best represents this metric?

A.The ratio of high-value intelligence reports produced that directly answered PIRs versus total raw data collected
B.The number of firewall rule changes approved by change management
C.The total financial cost of commercial intelligence subscriptions divided by the number of employees
D.The average time it takes an analyst to write a quarterly report
AnswerA

This metric evaluates whether the collection sources are yielding useful intelligence relative to the noise ingested.

Why this answer

Collection efficiency measures how effectively the sources being collected actually provide answers to the established PIRs, filtering out noise.

10
MCQhard

An intelligence manager is reviewing the threat intelligence program's intelligence gap analysis. The analysis reveals that the team frequently fails to detect supply chain intrusions until late in the attack lifecycle. Which adjustments to the direction and planning phase should the manager implement?

A.Disable all external threat intelligence feeds to reduce noise in the security operations center
B.Reassign all malware reverse engineering tasks to helpdesk support personnel
C.Shift intelligence requirements to focus on initial access vectors, third-party supplier dependencies, and forums frequented by Initial Access Brokers (IABs)
D.Increase the budget for automated SIEM log retention from 30 days to 90 days
AnswerC

Shifting focus to IABs and third-party dependencies targets the early stages of supply chain intrusions, closing the intelligence gap.

Why this answer

Refining collection requirements and pivoting focus toward upstream threat indicators (such as supplier dependencies, third-party vendor risks, and initial access brokers) addresses late detection of supply chain intrusions.

11
Multi-Selecthard

An intelligence manager is evaluating sources for a threat intelligence program during the planning phase. Which TWO criteria are critical when vetting a new external threat intelligence vendor or feed? (Choose TWO)

Select 2 answers
A.Relevance of the feed data to the organization's specific industry sector and geographic footprint
B.The marketing budget of the threat intelligence vendor
C.Whether the vendor shares all threat data publicly on open-source social media platforms
D.Actionability of the intelligence provided, allowing security controls to be updated effectively
E.The total number of unverified IP addresses included in the feed without regard to false positive rates
AnswersA, D

Feeds must be relevant to the specific industry and region to be useful.

Why this answer

When vetting threat intelligence feeds or vendors, relevance to the organization's specific threat landscape and actionability of the data are paramount.

12
Multi-Selecthard

An organization is conducting a review of its threat intelligence program to assess alignment with intelligence-driven defense models. Which TWO frameworks are widely used to structure threat intelligence planning, collection, and defense operations? (Choose TWO)

Select 2 answers
A.Lockheed Martin Cyber Kill Chain
B.Simple Mail Transfer Protocol (SMTP) specification
C.Hypertext Transfer Protocol Secure (HTTPS) RFC standards
D.Basic Input/Output System (BIOS) UEFI firmware specifications
E.MITRE ATT&CK Framework
AnswersA, E

The Cyber Kill Chain provides phases of cyber attacks, helping analysts structure intelligence collection and disruption strategies.

Why this answer

MITRE ATT&CK and the Lockheed Martin Cyber Kill Chain are core frameworks used in threat intelligence and defense planning.

13
MCQhard

An intelligence analyst is tasked with tailoring intelligence requirements for a merger and acquisition (M&A) scenario. Which methodology should be applied during the direction phase to identify threat actors specifically interested in compromising corporate transactions?

A.Target-Centric Intelligence Analysis
B.Network Forensic Packet Capture Analysis
C.Signature-Based Intrusion Detection Analysis
D.Vulnerability Scoring via CVSS v3.1 Base Metrics
AnswerA

Target-centric analysis focuses on a specific entity, event, or transaction (like an M&A), aligning collection requirements around actors targeting that specific asset.

Why this answer

Target-centric intelligence analysis focuses specifically on the assets, events, or transactions of interest (such as an M&A deal) and maps out all threat actors known to target those specific equities.

14
MCQeasy

When building a Threat Intelligence team, the Chief Information Security Officer (CISO) must decide between centralizing the TI function or distributing analysts across various business units. What is a primary advantage of a centralized TI team structure?

A.Elimination of the need for external commercial threat feeds
B.Standardization of intelligence processes and a unified view of organizational risk
C.Complete elimination of communication silos with local IT helpdesks
D.Faster deployment of endpoint agents on localized operational technology networks
AnswerB

Centralization ensures consistent methodologies, tool usage, and cohesive reporting across the entire organization.

Why this answer

A centralized team allows for better standardization of intelligence processes, resource pooling, and a unified view of the enterprise threat landscape.

15
Multi-Selectmedium

During the threat landscape analysis and requirements gathering process, an organization must identify its critical assets and crown jewels. Which THREE categories represent typical critical assets that should drive intelligence requirements? (Choose THREE)

Select 3 answers
A.Core industrial control systems or production manufacturing IT/OT infrastructure
B.Publicly available marketing brochures hosted on the corporate website
C.Customer Personally Identifiable Information (PII) and financial records
D.Breakroom snack inventory logs
E.Proprietary source code and intellectual property
AnswersA, C, E

Production infrastructure and ICS/OT systems are critical assets whose compromise impacts business operations.

Why this answer

Critical assets driving CTI requirements typically include intellectual property, customer Personally Identifiable Information (PII), and core operational infrastructure.

16
MCQmedium

A newly formed CTI team is conducting stakeholder interviews to establish intelligence requirements. The Chief Risk Officer (CRO) expresses concern over ransomware supply chain disruptions. How should the intelligence analyst translate this concern into a formal intelligence requirement?

A.Develop requirements to identify ransomware campaigns, threat actor TTPs, and third-party vendors targeting our critical supply chain ecosystem
B.Collect all CVEs published daily by the National Vulnerability Database (NVD)
C.Deploy endpoint detection and response (EDR) agents to all contractor laptops
D.Execute regular phishing simulations for all internal business unit employees
AnswerA

This directly addresses the CRO's concern by focusing collection and analysis on supply chain threat actors, TTPs, and campaigns.

Why this answer

Translating executive concerns into formal requirements involves formulating specific, answerable questions regarding supply chain vulnerabilities and active ransomware campaigns targeting third-party vendors.

17
MCQeasy

During the planning phase of building a CTI team, the program manager needs to define the scope of intelligence operations. Which category of intelligence focuses specifically on technical indicators such as file hashes, IP addresses, and domain names?

A.Financial Intelligence
B.Operational Intelligence
C.Tactical Intelligence
D.Strategic Intelligence
AnswerC

Tactical intelligence consists of technical IOCs, IP addresses, domains, and file hashes used by defenders and security controls.

Why this answer

Tactical threat intelligence focuses on low-level indicators of compromise (IOCs), hashes, IPs, and domains used by automated security defenses.

18
Multi-Selectmedium

During program planning for a CTI team, the program manager must define stakeholder engagement protocols. Which THREE stakeholder groups should be actively engaged during the requirements planning and review phases? (Choose THREE)

Select 3 answers
A.Residential landscaping contractors
B.Executive Leadership and Risk Management (CISO, CRO)
C.Security Operations Center (SOC) managers
D.Incident Response (IR) team leads
E.External catering service providers
AnswersB, C, D

Executives provide strategic context and require risk-aligned intelligence reporting.

Why this answer

Engaging Incident Response, Security Operations, and Executive Management ensures that CTI requirements align with operational needs and executive risks.

19
MCQmedium

A CTI program manager is defining Key Performance Indicators (KPIs) to measure the effectiveness of the intelligence program during the review phase. Which metric best measures the quality and relevance of the intelligence produced?

A.Number of threat intelligence blog posts published on the corporate website
B.Percentage of intelligence reports that result in actionable security controls or detection rules
C.Total gigabytes of threat data ingested from commercial feeds per month
D.Total number of security alerts generated by the SIEM
AnswerB

Actionability and downstream adoption directly reflect the quality and operational value of the intelligence.

Why this answer

Measuring actionable outcomes, such as the percentage of intelligence reports that lead to confirmed threat mitigation or detection rule creation, evaluates quality and relevance.

20
MCQhard

An intelligence analyst is performing a threat landscape analysis using the Cyber Kill Chain framework. During the planning phase, the analyst wants to map collection requirements to disrupt adversaries during the 'Weaponization' phase. What specific intelligence should the analyst plan to collect?

A.Phishing email headers received by internal mail servers from external domains
B.File hashes and indicators associated with credential dumping tools like Mimikatz
C.Network traffic logs showing data exfiltration over encrypted channels
D.Information on exploit frameworks, payload construction tools, and customized delivery mechanisms used by target threat groups
AnswerD

Weaponization focuses on combining exploits and payloads, making intelligence on builder tools and exploit frameworks relevant.

Why this answer

Weaponization involves coupling an exploit with a payload (e.g., a PDF or Office document). Collecting intelligence on weaponization involves gathering data on exploit kits, payload templates, and builder tools used by adversaries.

21
Multi-Selecteasy

An intelligence analyst is drafting the collection management framework during the planning phase. Which TWO activities are key components of collection management? (Choose TWO)

Select 2 answers
A.Tasking collection assets and monitoring the flow of raw intelligence data
B.Conducting corporate financial payroll audits
C.Configuring office building climate control thermostats
D.Writing custom assembly code for rootkit deployment
E.Identifying and evaluating intelligence sources and collection feeds against stated PIRs
AnswersA, E

Tasking sources and overseeing data flow are core operational responsibilities of collection management.

Why this answer

Collection management involves identifying and acquiring sources to answer intelligence requirements while monitoring collection performance.

22
MCQhard

During program planning for a threat intelligence capability, the security team maps their intelligence processes to the NIST Cybersecurity Framework (CSF). Which CSF function is most directly aligned with establishing Threat Intelligence requirements, gathering sources, and reviewing intelligence collection efficacy?

A.Recover (RC)
B.Identify (ID)
C.Respond (RS)
D.Protect (PR)
AnswerB

The Identify function includes asset management, business environment assessment, and risk assessment tasks that drive intelligence requirements.

Why this answer

The NIST CSF 'Govern' (GV) and 'Identify' (ID) functions encompass the establishment of policies, procedures, and asset/threat identification, with ID.RA (Risk Assessment) and GV subcategories guiding intelligence requirement definition.

23
MCQhard

A CTI team is conducting a threat landscape analysis for a global financial institution. The analyst wants to apply the Diamond Model of Intrusion Analysis during the requirements planning phase to scope out potential adversary capabilities and infrastructure requirements. Which vertex of the Diamond Model directly captures the tools and techniques used by the adversary?

A.Infrastructure
B.Capability
C.Adversary
D.Victim
AnswerB

Capability captures the specific software, tools, exploits, and techniques utilized by the adversary against the victim.

Why this answer

In the Diamond Model, the four core vertices are Adversary, Capability, Infrastructure, and Victim. Capability represents the tools and techniques (TTPs) used by the adversary.

24
MCQeasy

During the CTI team building process, the manager needs to hire personnel with analytical mindsets who can avoid cognitive biases. Which cognitive bias involves favoring information that confirms pre-existing beliefs while discarding contradictory evidence?

A.Availability Heuristic
B.Mirror Imaging
C.Bandwagon Effect
D.Confirmation Bias
AnswerD

Confirmation bias describes the tendency to notice and accept evidence supporting one's hypothesis while ignoring contradictory data.

Why this answer

Confirmation bias is the tendency to search for, interpret, favor, and recall information in a way that confirms or supports one's prior beliefs or values.

Ready to test yourself?

Try a timed practice session using only Requirements Planning Direction And Review questions.