Courseiva

Certified Threat Intelligence Analyst (312-85) (312-85) — Questions 76150

195 questions total · 3pages · All types, answers revealed

Page 1

Page 2 of 3

Page 3
76
Multi-Selectmedium

Which TWO methods are effective for visualizing threat actor TTPs within a CTI report?

Select 2 answers
A.A bibliography of all external sources.
B.A photograph of the threat actor.
C.A raw list of every log entry captured.
D.Flow diagrams illustrating the attack execution sequence.
E.Heat maps indicating TTP frequency or coverage.
AnswersD, E

Flows show how TTPs link together.

Why this answer

Mapping to frameworks (MITRE) and flow diagrams are the most effective ways to visualize TTPs.

77
MCQhard

A threat intelligence report uses the Diamond Model for Intrusion Analysis. You are adding a new 'Victim' node. What information should you include to align with this model?

A.The malware hash used in the attack
B.The TTPs used by the attacker
C.The IP addresses of the attacker's C2
D.The specific organization or target being attacked
AnswerD

The Victim node identifies the entity receiving the attack.

Why this answer

The Diamond Model focuses on the relationship between Adversary, Capability, Infrastructure, and Victim. The Victim node represents the organization or individual being targeted.

78
MCQmedium

You are assessing a threat actor's 'Capability'. Which of the following would be considered a CTI Capability indicator?

A.The target organization's industry sector
B.The use of a custom remote access trojan (RAT) with specific DGA algorithms
C.The frequency of the adversary's campaigns
D.The adversary's base of operations in a specific country
AnswerB

Custom malware is a core example of an adversary's capability.

Why this answer

Capability refers to the specific tools, malware, or techniques an adversary uses to achieve their objectives.

79
Multi-Selectmedium

Which TWO of the following are valid ways to improve the reliability of threat intelligence data?

Select 2 answers
A.Removing all metadata.
B.Increasing the ingest frequency.
C.Cross-referencing indicators across multiple sources.
D.Validating the source authenticity.
E.Automatically trusting all feeds.
AnswersC, D

Verification against multiple sources improves accuracy.

Why this answer

Data reliability is improved through source verification and cross-referencing indicators across multiple platforms.

80
Multi-Selectmedium

Which THREE actions should a SOC team perform when a high-confidence indicator is received via a threat intelligence feed?

Select 3 answers
A.Disable all network interfaces
B.Initiate threat hunting across endpoints
C.Validate against internal historical logs
D.Automate blocking at the perimeter
E.Publicly disclose the intelligence
AnswersB, C, D

Check for latent infections.

Why this answer

High-confidence indicators should be validated against internal logs, the firewall/proxy should be updated to block the activity, and the threat should be hunted for historical presence.

81
MCQeasy

Which component of the threat intelligence lifecycle involves the conversion of raw data into a format suitable for analysis?

A.Collection
B.Processing
C.Dissemination
D.Analysis
AnswerB

Processing is the step where raw data is structured for analysis.

Why this answer

Processing involves tasks like data normalization, translation, and decryption to make raw data ready for analysis.

82
Multi-Selectmedium

Which TWO of the following are considered 'Indicator of Compromise' (IOC) types?

Select 2 answers
A.SHA-256 File Hash
B.Server rack temperature
C.C2 Domain name
D.Employee behavior patterns
E.Project management timeline
AnswersA, C

File hashes are classic atomic IOCs.

Why this answer

IOCs are typically digital forensic artifacts like file hashes or network connection logs.

83
Multi-Selecthard

Which TWO aspects of a threat intelligence report are most useful for long-term strategic risk management decisions?

Select 2 answers
A.Long-term trend forecasting
B.Incident response ticket numbers
C.Threat actor motivation analysis
D.Specific file hashes
E.Firewall rule recommendations
AnswersA, C

Informs future budget and control strategy.

Why this answer

Strategic decisions rely on understanding the threat actor's motivations and the long-term trends identified in the intelligence.

84
Multi-Selecthard

Which THREE of the following are valid Traffic Light Protocol (TLP) labels?

Select 3 answers
A.TLP:INTERNAL
B.TLP:AMBER
C.TLP:RED
D.TLP:GREEN
E.TLP:PRIVATE
AnswersB, C, D

Standard TLP label.

Why this answer

The current TLP standards are RED, AMBER, GREEN, and CLEAR.

85
MCQmedium

An organization is establishing metrics for its Threat Intelligence program review. The CTI director wants to measure 'Collection Efficiency.' Which formula or evaluation method best represents this metric?

A.The ratio of high-value intelligence reports produced that directly answered PIRs versus total raw data collected
B.The number of firewall rule changes approved by change management
C.The total financial cost of commercial intelligence subscriptions divided by the number of employees
D.The average time it takes an analyst to write a quarterly report
AnswerA

This metric evaluates whether the collection sources are yielding useful intelligence relative to the noise ingested.

Why this answer

Collection efficiency measures how effectively the sources being collected actually provide answers to the established PIRs, filtering out noise.

86
Multi-Selectmedium

Which TWO of the following are common methods used to normalize threat data from disparate sources?

Select 2 answers
A.Deleting all historical data.
B.Standardizing time formats (e.g., UTC).
C.Increasing the firewall throughput.
D.Disabling API authentication.
E.Mapping to a common schema (e.g., STIX).
AnswersB, E

Normalization requires time synchronization.

Why this answer

Normalization involves mapping diverse data to a common schema and standardizing fields like time and identity.

87
MCQmedium

Which protocol is most commonly used for the automated transport of machine-readable threat intelligence, specifically designed to support the STIX format?

A.SNMP
B.Syslog
C.ICMP
D.TAXII
AnswerD

TAXII is the industry standard for transporting STIX.

Why this answer

TAXII (Trusted Automated eXchange of Intelligence Information) is the application-layer protocol designed specifically to transport STIX information.

88
Multi-Selectmedium

Which TWO of the following are primary components of the 'Adversary' node in the Diamond Model? (Choose two)

Select 2 answers
A.Intrusion Set / Threat Actor identity
B.Network infrastructure
C.Target organization's industry
D.Adversary motivation
E.Malware capabilities
AnswersA, D

The actor profile is the primary component of this node.

Why this answer

The Adversary node includes the actors behind the threat and their intent.

89
MCQhard

You are integrating a dark web monitoring feed into your TIP. The data arrives as unstructured text. What is the most effective first step in the data processing pipeline?

A.Application of NLP techniques to extract entities.
B.Hashing the entire document.
C.Direct ingestion into the SIEM.
D.Manual entry into a spreadsheet.
AnswerA

NLP automates the extraction of IOCs from unstructured text.

Why this answer

NLP (Natural Language Processing) is the standard technique for converting unstructured text into structured, normalized intelligence.

90
Multi-Selectmedium

Which TWO of the following are common actions performed during the 'processing' phase of the threat intelligence lifecycle?

Select 2 answers
A.Normalization to a unified format.
B.Parsing of raw data files.
C.Physical installation of servers.
D.Writing incident response playbooks.
E.Final delivery to the CISO.
AnswersA, B

Normalization is essential to make data usable.

Why this answer

Data processing focuses on transforming raw data into useful information, typically through parsing and normalization.

91
MCQmedium

When evaluating an adversary's TTPs, you notice they use 'Process Hollowing'. Which ATT&CK Tactic does this technique primarily support?

A.Lateral Movement
B.Credential Access
C.Persistence
D.Defense Evasion
AnswerD

Defense Evasion covers techniques used to avoid detection throughout the lifecycle.

Why this answer

Process Hollowing is a form of Defense Evasion, as it allows malicious code to hide inside a legitimate process.

92
MCQmedium

A security analyst is using the Diamond Model to document an incident. The analyst notes that the adversary used a specific Command and Control (C2) server IP address. In the context of the Diamond Model, where does this IP address belong?

A.Capability
B.Infrastructure
C.Adversary
D.Victim
AnswerB

Infrastructure captures the C2 nodes and tools used to facilitate the attack.

Why this answer

In the Diamond Model, Infrastructure represents the physical and logical communication paths and services, such as IPs and domains, used by the adversary.

93
MCQeasy

Which of the following is a primary benefit of using a 'Diamond Model' of intrusion analysis in your threat report?

A.It enables the visualization of relationships between the four core components of an intrusion.
B.It provides a vulnerability score for every asset.
C.It calculates the financial loss expectancy of a breach.
D.It replaces the need for SIEM log collection.
AnswerA

The Diamond Model maps the nexus of Adversary, Capability, Infrastructure, and Victim.

Why this answer

The Diamond Model links the Adversary, Capability, Infrastructure, and Victim, providing a holistic view of the event.

94
Multi-Selecthard

Which THREE of the following are security best practices for managing a TAXII server?

Select 3 answers
A.Enforce TLS 1.2 or higher
B.Implement strict API key management
C.Audit server access logs regularly
D.Use plain text HTTP for better performance
E.Disable all authentication
AnswersA, B, C

Secures data in transit.

Why this answer

Securing a TAXII server involves access control, TLS, and monitoring logs.

95
MCQmedium

During an IR engagement, you observe a beaconing pattern to a suspicious domain. Which tool feature in Wireshark would you use to export domain names for further analysis against your TI feed?

A.Export Objects
B.Follow TCP Stream
C.Endpoints
D.Expert Information
AnswerA

This feature extracts artifacts from captured traffic.

Why this answer

'Export Objects' allows you to extract HTTP or DNS data, including domain names, from a PCAP file.

96
MCQhard

An intelligence manager is reviewing the threat intelligence program's intelligence gap analysis. The analysis reveals that the team frequently fails to detect supply chain intrusions until late in the attack lifecycle. Which adjustments to the direction and planning phase should the manager implement?

A.Disable all external threat intelligence feeds to reduce noise in the security operations center
B.Reassign all malware reverse engineering tasks to helpdesk support personnel
C.Shift intelligence requirements to focus on initial access vectors, third-party supplier dependencies, and forums frequented by Initial Access Brokers (IABs)
D.Increase the budget for automated SIEM log retention from 30 days to 90 days
AnswerC

Shifting focus to IABs and third-party dependencies targets the early stages of supply chain intrusions, closing the intelligence gap.

Why this answer

Refining collection requirements and pivoting focus toward upstream threat indicators (such as supplier dependencies, third-party vendor risks, and initial access brokers) addresses late detection of supply chain intrusions.

97
Multi-Selecthard

An intelligence manager is evaluating sources for a threat intelligence program during the planning phase. Which TWO criteria are critical when vetting a new external threat intelligence vendor or feed? (Choose TWO)

Select 2 answers
A.Relevance of the feed data to the organization's specific industry sector and geographic footprint
B.The marketing budget of the threat intelligence vendor
C.Whether the vendor shares all threat data publicly on open-source social media platforms
D.Actionability of the intelligence provided, allowing security controls to be updated effectively
E.The total number of unverified IP addresses included in the feed without regard to false positive rates
AnswersA, D

Feeds must be relevant to the specific industry and region to be useful.

Why this answer

When vetting threat intelligence feeds or vendors, relevance to the organization's specific threat landscape and actionability of the data are paramount.

98
MCQhard

You are hunting for Cobalt Strike C2 using JA3/JA3S fingerprinting. If the JA3S value is unique for your environment and observed across multiple hosts, what does this suggest?

A.The connection is encrypted with an expired certificate
B.The client has been compromised
C.It indicates a specific C2 listener implementation
D.It is a standard browser connection
AnswerC

Malicious C2 servers often have consistent, non-standard TLS handshakes that generate unique JA3S fingerprints.

Why this answer

A unique JA3S value in a specific environment often points to a specific server-side implementation of a C2 listener.

99
MCQmedium

You are configuring a TAXII client to pull STIX 2.1 data from a commercial threat intelligence platform. During testing, the client reports a 406 Not Acceptable error. What is the most likely cause?

A.The connection is blocked by a firewall ACL.
B.The API key provided for authentication is expired.
C.The client requested an unsupported content-type in the Accept header.
D.The TAXII discovery service endpoint is misconfigured.
AnswerC

The 406 error specifically relates to content negotiation failure.

Why this answer

A 406 error typically indicates that the media type requested in the Accept header is not supported by the TAXII server, often due to a mismatch between STIX versioning expectations.

100
Multi-Selectmedium

You are auditing your TAXII server configuration for data sharing compliance. Which TWO of the following items must be explicitly defined for each collection to ensure correct data governance and access control?

Select 2 answers
A.Database indexing strategy
B.Default STIX versioning
C.Access Control Lists (ACLs)
D.Server uptime SLA
E.Content filtering criteria
AnswersC, E

ACLs define who can read from or write to the collection.

Why this answer

TAXII collections require defined access controls and content selection (filters) to ensure only authorized entities receive specific intelligence.

101
Multi-Selecthard

An organization is conducting a review of its threat intelligence program to assess alignment with intelligence-driven defense models. Which TWO frameworks are widely used to structure threat intelligence planning, collection, and defense operations? (Choose TWO)

Select 2 answers
A.Lockheed Martin Cyber Kill Chain
B.Simple Mail Transfer Protocol (SMTP) specification
C.Hypertext Transfer Protocol Secure (HTTPS) RFC standards
D.Basic Input/Output System (BIOS) UEFI firmware specifications
E.MITRE ATT&CK Framework
AnswersA, E

The Cyber Kill Chain provides phases of cyber attacks, helping analysts structure intelligence collection and disruption strategies.

Why this answer

MITRE ATT&CK and the Lockheed Martin Cyber Kill Chain are core frameworks used in threat intelligence and defense planning.

102
MCQhard

An analyst is mapping internal incident data to STIX 2.1 objects. You need to link a specific threat actor to the infrastructure they recently utilized. Which object type should you use to link the 'Threat-Actor' object to the 'Infrastructure' object?

A.Indicator
B.Sighting
C.Relationship
D.Observed-Data
AnswerC

The Relationship SDO is the formal mechanism to link two SDOs.

Why this answer

In STIX 2.1, the 'Relationship' object is specifically used to connect two SDOs (Domain Objects) with a defined relationship type such as 'uses'.

103
MCQmedium

You are drafting a STIX 2.1 'Observed-Data' object to report an IP address involved in a recent exfiltration event. To maintain standard compliance for automated ingestion, which property is mandatory to define the temporal scope of the observation?

A.'first_observed'
B.'confidence'
C.'created_by_ref'
D.'object_marking_refs'
AnswerA

This property is mandatory to specify when the observation began.

Why this answer

The 'first_observed' and 'last_observed' properties are required in the STIX 2.1 Observed-Data SDO to provide context for the timeline of the data collection.

104
MCQhard

You are managing threat intelligence in a cloud-native environment. You need to identify indicators related to unauthorized API key usage in AWS. Which AWS service provides the most relevant CTI data for this investigation?

A.AWS CloudTrail
B.AWS GuardDuty
C.AWS WAF
D.AWS Inspector
E.AWS Config
AnswerA

CloudTrail logs provide the event history, including the user, time, and IP address for every API call.

Why this answer

AWS CloudTrail provides the audit logs of all API calls made in the account, which is essential for identifying unauthorized usage.

105
Multi-Selectmedium

You are reviewing your organization's threat modeling process. Which TWO of the following are considered essential components to include when documenting a threat model?

Select 2 answers
A.A list of identified threats categorized by type.
B.A detailed system architecture diagram.
C.The budget allocated for the security team.
D.The employee handbook for the IT department.
E.A list of all employees with admin access.
AnswersA, B

Categorizing threats is necessary for prioritization.

Why this answer

Documentation must define the scope of the system and the potential threats identified against that scope.

106
Multi-Selecthard

Which THREE data sources are typically analyzed when investigating an insider threat according to security behavior analytics?

Select 3 answers
A.Employee cafeteria transaction history.
B.Sensitive file access and data movement tracking.
C.System authentication and login/logout logs.
D.Email or messaging communication traffic metadata.
E.Public internet speed test results.
AnswersB, C, D

Detects unauthorized exfiltration.

Why this answer

Insider threats are detected via access logs, file activity, and network communication patterns.

107
MCQhard

In an ACH matrix, you have assigned values to the diagnostic evidence. You observe that a specific hypothesis has the lowest score. What does this indicate about the hypothesis?

A.The hypothesis is the most likely scenario.
B.The hypothesis is heavily supported by available data.
C.The hypothesis is the least likely to be correct given the current evidence set.
D.The hypothesis lacks enough evidence to be evaluated.
AnswerC

The hypothesis with the lowest score is typically the one most inconsistent with the available diagnostic evidence.

Why this answer

In ACH, lower scores in the matrix often indicate that the evidence strongly contradicts the hypothesis.

108
MCQhard

You are setting up a STIX-to-SIEM pipeline. The SIEM requires data in CSV format. What is the critical step in your data processing architecture?

A.Ignore the format mismatch.
B.Develop an ETL/transformation script.
C.Enable automatic STIX parsing in the SIEM engine.
D.Increase the SIEM storage capacity.
AnswerB

Transforming data formats is the core of the ETL process.

Why this answer

You must implement a transformation layer (often using a library or script) to map the JSON STIX structure to the required CSV columns.

109
MCQhard

You are performing threat hunting based on the Diamond Model. You identified a new Infrastructure node (IP). What is the logical next step in the Diamond Model analysis?

A.Update the firewall blacklist only
B.Change all user passwords
C.Pivot to identify the Capability or Adversary
D.Close the incident ticket
AnswerC

Pivoting is the core of the Diamond Model analysis to link vertices.

Why this answer

After identifying infrastructure, the next step is to pivot to identify the associated Capability or Adversary, creating a chain of evidence.

110
MCQeasy

Which of the following is an example of 'structured' threat intelligence data?

A.An email body.
B.A STIX 2.1 JSON file.
C.A handwritten note.
D.A PDF report from a vendor.
AnswerB

STIX is a structured standard.

Why this answer

STIX/TAXII provides a machine-readable, structured format for intelligence.

111
Multi-Selectmedium

Which TWO log sources are most essential when hunting for adversary use of living-off-the-land binaries (LotL)?

Select 2 answers
A.Sysmon Event ID 1
B.System Event Log (Event ID 7045)
C.DHCP Server logs
D.DNS Query logs
E.Security Event Log (Event ID 4688)
AnswersA, E

Essential for process genealogy and SHA256 hashing.

Why this answer

Security logs (4688) capture process launches with command lines, while Sysmon (Event ID 1) provides the parent-child context and hash data.

112
MCQhard

An intelligence analyst is tasked with tailoring intelligence requirements for a merger and acquisition (M&A) scenario. Which methodology should be applied during the direction phase to identify threat actors specifically interested in compromising corporate transactions?

A.Target-Centric Intelligence Analysis
B.Network Forensic Packet Capture Analysis
C.Signature-Based Intrusion Detection Analysis
D.Vulnerability Scoring via CVSS v3.1 Base Metrics
AnswerA

Target-centric analysis focuses on a specific entity, event, or transaction (like an M&A), aligning collection requirements around actors targeting that specific asset.

Why this answer

Target-centric intelligence analysis focuses specifically on the assets, events, or transactions of interest (such as an M&A deal) and maps out all threat actors known to target those specific equities.

113
MCQhard

While hunting for living-off-the-land (LotL) binaries, you identify suspicious use of 'certutil.exe'. What is the most likely malicious purpose for this utility?

A.Downloading remote payloads
B.Extracting browser passwords
C.Clearing event logs
D.Modifying system registry keys
AnswerA

The -urlcache flag is a common bypass used to fetch payloads.

Why this answer

Certutil.exe is frequently abused to download files from remote URLs using the -urlcache -split -f flags.

114
MCQeasy

What does a high 'CVSS' score indicate in the context of vulnerability data analysis?

A.The vulnerability is currently being exploited in the wild.
B.The vulnerability affects only Windows systems.
C.The vulnerability has a high severity rating based on its characteristics.
D.The vulnerability is already patched.
AnswerC

CVSS is a scoring system for vulnerability severity.

Why this answer

CVSS scores represent the severity of a vulnerability, with higher scores indicating higher severity.

115
MCQmedium

During the 'Direction' phase of the threat intelligence lifecycle, your stakeholder requests a focus on 'Supply Chain threats'. How should you refine this requirement?

A.Ignore the request until more data is available
B.Purchase all available supply chain threat reports
C.Automate the collection of all supply chain news
D.Define specific PIRs regarding third-party software vendors and update frequency
AnswerD

Defining PIRs makes the intelligence requirement actionable.

Why this answer

Refining requirements involves transforming abstract topics into measurable intelligence needs (Priority Intelligence Requirements).

116
MCQeasy

In the threat intelligence lifecycle, what is the 'Dissemination' phase primarily concerned with?

A.Analyzing the data collected
B.Collecting data from the dark web
C.Developing new security tools
D.Ensuring the intelligence is delivered effectively to the target audience
AnswerD

Dissemination is about the delivery of the intelligence product.

Why this answer

Dissemination focuses on ensuring the right information reaches the right person in the right format at the right time.

117
MCQeasy

When building a Threat Intelligence team, the Chief Information Security Officer (CISO) must decide between centralizing the TI function or distributing analysts across various business units. What is a primary advantage of a centralized TI team structure?

A.Elimination of the need for external commercial threat feeds
B.Standardization of intelligence processes and a unified view of organizational risk
C.Complete elimination of communication silos with local IT helpdesks
D.Faster deployment of endpoint agents on localized operational technology networks
AnswerB

Centralization ensures consistent methodologies, tool usage, and cohesive reporting across the entire organization.

Why this answer

A centralized team allows for better standardization of intelligence processes, resource pooling, and a unified view of the enterprise threat landscape.

118
MCQhard

In a threat intelligence lifecycle, what is the specific role of the 'Dissemination' phase in relation to the IR team?

A.Defining incident response procedures
B.Validating the data source reliability
C.Delivering intelligence in a usable, timely format
D.Archiving incident data
AnswerC

Dissemination is about the delivery of insights to the right stakeholders.

Why this answer

Dissemination ensures that relevant, actionable intelligence reaches the IR team in a format they can immediately use for investigation.

119
Multi-Selecthard

Which THREE of the following are primary components (vertices) of the Diamond Model of Intrusion Analysis?

Select 3 answers
A.Network Topology
B.Payload
C.Capability
D.Infrastructure
E.Adversary
AnswersC, D, E

The tools/techniques used.

Why this answer

The four core vertices of the Diamond Model are Adversary, Capability, Infrastructure, and Victim.

120
MCQeasy

You are reviewing the Diamond Model of Intrusion Analysis for a recent incident. The 'Victim' node is populated with the targeted organization's identity. Which element should be populated in the 'Infrastructure' node?

A.The time of day the attack occurred
B.The IP addresses of the Command and Control servers used
C.The specific malware hash used in the attack
D.The adversary's primary motivation
AnswerB

C2 infrastructure is a hallmark example of the Infrastructure node.

Why this answer

The Infrastructure node in the Diamond Model describes the physical or logical communication channels used by the adversary, such as C2 servers or IP addresses.

121
MCQhard

You are using the MITRE ATT&CK framework to map an adversary's actions. The adversary uses 'PowerShell' to execute commands on the victim. Which Tactic does this fall under?

A.Persistence
B.Exfiltration
C.Execution
D.Privilege Escalation
AnswerC

Execution is the tactic of running code on the victim system.

Why this answer

Execution is the tactic used to run malicious code on a target system; PowerShell is a common technique within that tactic.

122
Multi-Selectmedium

Which TWO file integrity monitoring (FIM) events would be most useful to detect potential unauthorized persistence mechanisms?

Select 2 answers
A.Creation of files in C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp
B.Access to C:\Windows\System32\drivers\etc\hosts
C.Modification of HKLM\Software\Microsoft\Windows\CurrentVersion\Run
D.Changes to desktop background images
E.Reading of browser profile files
AnswersA, C

Common user-land persistence.

Why this answer

Monitoring changes to Startup folders and registry Run keys are essential to detect persistence.

123
MCQhard

During a threat modeling session, you are analyzing a system's 'Attack Surface'. You decide to apply the 'Least Privilege' principle. Which specific analysis technique are you practicing to reduce potential pathways?

A.Threat Vector Analysis
B.Risk Likelihood Assessment
C.Threat Actor Attribution
D.Attack Surface Reduction
AnswerD

Restricting permissions is a direct method of reducing the attack surface.

Why this answer

Attack Surface reduction through Least Privilege is a foundational technique in threat modeling aimed at minimizing the damage potential of a compromise.

124
MCQeasy

When collecting data from open-source intelligence (OSINT) sources, what is the primary risk associated with automated scraping without rate-limit awareness?

A.Lack of data encryption.
B.STIX version mismatch.
C.Data normalization failure.
D.Source IP blacklisting.
AnswerD

Service providers block IPs that exceed defined rate thresholds.

Why this answer

Automated scraping without respect for rate limits often leads to IP blacklisting by the source provider.

125
MCQhard

During an investigation, you observe an attacker utilizing a custom-compiled Trojan that bypasses EDR detection. According to the Cyber Kill Chain, at which phase is this specific action of developing the custom tool occurring?

A.Weaponization
B.Exploitation
C.Delivery
D.Installation
AnswerA

Weaponization involves the creation of the malicious artifact intended for the victim.

Why this answer

The Weaponization phase is where the adversary creates the malicious payload or tool, such as a custom Trojan, to exploit the target.

126
MCQhard

When disseminating intelligence to C-level executives versus technical SOC analysts, you must adjust your reporting format. Which technique ensures compliance with intelligence cycle requirements for 'Actionable Intelligence'?

A.Convert all technical reports to PDF only, removing machine-readable STIX.
B.Include raw PCAP files in all executive reports.
C.Remove TLP markings from executive reports to increase accessibility.
D.Use 'Executive Summaries' that highlight business impact and risk, while keeping technical IOCs in an attached appendix.
AnswerD

This approach ensures the strategic needs are met while providing necessary technical depth for further investigation.

Why this answer

Actionable intelligence must be tailored to the audience; executives require strategic summaries (impact and risk), while analysts require technical indicators (IOCs).

127
Multi-Selectmedium

Which THREE types of information should be collected during the 'Processing' phase of the intelligence cycle to ensure data quality?

Select 3 answers
A.Physical media scanning
B.Enrichment with context
C.Normalization of data formats
D.Deduplication of entries
E.Executive sign-off
AnswersB, C, D

Adds value to the raw data.

Why this answer

Data quality is ensured by normalizing formats, removing duplicates, and enriching data with context from other sources.

128
MCQhard

While conducting a threat modeling exercise using STRIDE, you are analyzing a cloud-based API gateway. You notice that authentication tokens are being logged in plain text in the debugging logs. Which threat category in STRIDE is most specifically violated here?

A.Elevation of Privilege
B.Information Disclosure
C.Tampering
D.Repudiation
AnswerB

Logging sensitive credentials is a direct failure of confidentiality.

Why this answer

STRIDE stands for Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. Plain text logging of tokens is a classic Information Disclosure vulnerability.

129
Multi-Selecthard

Which THREE of the following are key components of a STIX 2.1 'Indicator' object?

Select 3 answers
A.valid_from
B.confidence
C.firewall_acl_rule
D.user_password_hash
E.pattern
AnswersA, B, E

Validity dates are standard properties.

Why this answer

The Indicator object in STIX 2.1 contains specific properties including the pattern, validity period, and confidence score.

130
MCQeasy

Which of the following is a primary 'push' source for threat intelligence in an enterprise SOC?

A.Commercial threat feed
B.Internal log analysis
C.Packet capture
D.Manual web research
AnswerA

Commercial feeds are designed to push data to subscribers.

Why this answer

A commercial threat intelligence platform (TIP) or feed is typically a 'push' source, providing updates to the enterprise as they are identified.

131
Multi-Selectmedium

Which TWO types of intelligence are primarily categorized as 'Tactical' in nature?

Select 2 answers
A.Geopolitical threat assessments
B.Malware Hashes
C.Executive risk summaries
D.C2 IP addresses
E.Industry trend analysis
AnswersB, D

Hashes are tactical indicators.

Why this answer

Tactical intelligence is focused on immediate, technical indicators that can be used to stop an attack, such as IOCs and malware hashes.

132
MCQmedium

In Palo Alto Networks Cortex XSOAR, you are building a playbook to automate the qualification of incoming phishing alerts. Which integration command is used to calculate a 'reputation score' based on data from a connected threat intelligence platform (TIP)?

A.!fetchIntel
B.!getIndicatorScore
C.!updateReputation
D.!queryTI
AnswerB

This command standardizes reputation retrieval across integrated platforms.

Why this answer

The '!getIndicatorScore' command is the standard XSOAR automation command used to fetch and aggregate reputation scores from all integrated threat intelligence sources.

133
MCQeasy

When preparing a report for a SOC team, which metric is most important to include to prove the intelligence is actionable?

A.The total number of threat actors identified
B.The date the report was created
C.The TLP level
D.Confidence Score
AnswerD

The Confidence Score tells the analyst how reliable the data is for automated blocking.

Why this answer

The 'False Positive' rate or 'Confidence Score' helps SOC analysts prioritize which indicators to block versus which to monitor.

134
MCQhard

An organization wants to contribute intelligence to an ISAC (Information Sharing and Analysis Center). They need to ensure their sharing mechanism supports automated, near-real-time updates. Which standard should they adopt?

A.PDF report uploads
B.TAXII 2.1
C.Email distribution lists
D.SFTP file drops
AnswerB

TAXII 2.1 is the industry standard for real-time automated intelligence sharing.

Why this answer

TAXII is the transport protocol specifically designed for automated exchange of threat intelligence in real-time.

135
Multi-Selectmedium

During the threat landscape analysis and requirements gathering process, an organization must identify its critical assets and crown jewels. Which THREE categories represent typical critical assets that should drive intelligence requirements? (Choose THREE)

Select 3 answers
A.Core industrial control systems or production manufacturing IT/OT infrastructure
B.Publicly available marketing brochures hosted on the corporate website
C.Customer Personally Identifiable Information (PII) and financial records
D.Breakroom snack inventory logs
E.Proprietary source code and intellectual property
AnswersA, C, E

Production infrastructure and ICS/OT systems are critical assets whose compromise impacts business operations.

Why this answer

Critical assets driving CTI requirements typically include intellectual property, customer Personally Identifiable Information (PII), and core operational infrastructure.

136
Multi-Selecthard

Which THREE factors should be considered when evaluating the reliability of a threat intelligence vendor? (Choose three)

Select 3 answers
A.The vendor's track record for providing accurate, validated intelligence
B.The consistency of the vendor's reporting over time
C.The volume of indicators provided without context
D.The number of social media followers the vendor has
E.The vendor's ability to explain the methodology behind their reports
AnswersA, B, E

Historical accuracy is the most important indicator of reliability.

Why this answer

Reliability is determined by the vendor's transparency, consistency, and the quality of their data collection processes.

137
MCQmedium

A newly formed CTI team is conducting stakeholder interviews to establish intelligence requirements. The Chief Risk Officer (CRO) expresses concern over ransomware supply chain disruptions. How should the intelligence analyst translate this concern into a formal intelligence requirement?

A.Develop requirements to identify ransomware campaigns, threat actor TTPs, and third-party vendors targeting our critical supply chain ecosystem
B.Collect all CVEs published daily by the National Vulnerability Database (NVD)
C.Deploy endpoint detection and response (EDR) agents to all contractor laptops
D.Execute regular phishing simulations for all internal business unit employees
AnswerA

This directly addresses the CRO's concern by focusing collection and analysis on supply chain threat actors, TTPs, and campaigns.

Why this answer

Translating executive concerns into formal requirements involves formulating specific, answerable questions regarding supply chain vulnerabilities and active ransomware campaigns targeting third-party vendors.

138
MCQeasy

During the planning phase of building a CTI team, the program manager needs to define the scope of intelligence operations. Which category of intelligence focuses specifically on technical indicators such as file hashes, IP addresses, and domain names?

A.Financial Intelligence
B.Operational Intelligence
C.Tactical Intelligence
D.Strategic Intelligence
AnswerC

Tactical intelligence consists of technical IOCs, IP addresses, domains, and file hashes used by defenders and security controls.

Why this answer

Tactical threat intelligence focuses on low-level indicators of compromise (IOCs), hashes, IPs, and domains used by automated security defenses.

139
Multi-Selecthard

Which TWO components are mandatory for a valid STIX 2.1 'Indicator' object to function within an automated ingestion system?

Select 2 answers
A.created_by_ref
B.valid_from
C.pattern
D.pattern_type
E.confidence
AnswersC, D

The pattern defines the observable to look for.

Why this answer

An Indicator object requires a pattern (the detection logic) and a pattern_type (the language used, e.g., STIX pattern) to be parsed correctly.

140
MCQhard

When conducting a 'Sensitivity Analysis' on your threat model, what are you attempting to determine?

A.Whether the threat actor has successfully exfiltrated data.
B.How changes in input variables affect the model's output.
C.The total number of threat actors targeting the organization.
D.The cryptographic strength of the data being protected.
AnswerB

Sensitivity analysis tests the robustness of the model by varying inputs.

Why this answer

Sensitivity analysis determines how changes in individual input variables (like threat probability or asset value) impact the overall final output or risk calculation.

141
Multi-Selectmedium

During program planning for a CTI team, the program manager must define stakeholder engagement protocols. Which THREE stakeholder groups should be actively engaged during the requirements planning and review phases? (Choose THREE)

Select 3 answers
A.Residential landscaping contractors
B.Executive Leadership and Risk Management (CISO, CRO)
C.Security Operations Center (SOC) managers
D.Incident Response (IR) team leads
E.External catering service providers
AnswersB, C, D

Executives provide strategic context and require risk-aligned intelligence reporting.

Why this answer

Engaging Incident Response, Security Operations, and Executive Management ensures that CTI requirements align with operational needs and executive risks.

142
MCQeasy

Which of the following is a 'pull-based' method of threat intelligence data collection?

A.TAXII Poll.
B.Webhook notifications.
C.Email distribution lists.
D.RSS feeds.
AnswerA

A poll is an explicit request for data.

Why this answer

A TAXII client requesting data from a TAXII server (Poll) is a pull-based method.

143
MCQmedium

You are ingesting threat data into a TIP and notice that indicators lack 'TLP' (Traffic Light Protocol) markings. What is the standard industry procedure?

A.Assume TLP:RED.
B.Publish to public forums.
C.Discard the data entirely.
D.Assume TLP:CLEAR.
AnswerA

Standard practice is to default to the most restrictive level.

Why this answer

When TLP is missing, the default safest practice is to assume TLP:RED or the most restrictive category to prevent unauthorized disclosure.

144
MCQhard

You are troubleshooting a synchronization issue between two threat intelligence platforms. One platform is configured for TAXII 2.1 and the other is receiving the data but failing to parse the STIX 2.1 bundle. Which diagnostic step is most appropriate?

A.Restart the TAXII server service
B.Validate the JSON bundle against the STIX 2.1 schema
C.Check the TLS certificate expiration date
D.Check the firewall rules for port 443
AnswerB

Parsing errors are almost always due to non-compliant JSON structures.

Why this answer

Validating the JSON schema against the STIX 2.1 specification is the definitive way to identify structural inconsistencies in the received bundle.

145
MCQmedium

You are analyzing an intelligence report provided in STIX 2.1 format. You find an 'Identity' object being used to attribute the campaign. What is the most common use of the 'Identity' object in this context?

A.To represent the organization or individual performing or being targeted by an activity
B.To list the malware families used
C.To define the technical infrastructure of the attacker
D.To provide the IP addresses of the C2
AnswerA

The Identity object describes a person or organization involved in the activity.

Why this answer

The Identity object identifies the victim or the perpetrator, providing context on who is being targeted or who is performing the action.

146
Multi-Selecthard

Which THREE MITRE ATT&CK tactics are commonly involved in an adversary's effort to maintain a presence on a compromised system?

Select 3 answers
A.Exfiltration
B.Reconnaissance
C.Defense Evasion
D.Persistence
E.Privilege Escalation
AnswersC, D, E

Required to hide the persistence mechanism.

Why this answer

Persistence, Defense Evasion, and Privilege Escalation are essential for staying on a system and remaining undetected.

147
Multi-Selecthard

When setting up a TAXII 2.1 client, which THREE settings are mandatory for establishing a successful connection to a server?

Select 3 answers
A.Local proxy configuration
B.Server Discovery URL
C.API Root Identifier
D.Authentication Credentials
E.JSON Schema Validation path
AnswersB, C, D

The discovery URL is needed to find the API Root.

Why this answer

To connect to a TAXII server, you must provide the server URL, valid credentials, and the API root identifier.

148
MCQmedium

An adversary is performing internal reconnaissance using 'net view' commands. In the MITRE ATT&CK framework, which technique ID maps to this behavior?

A.T1071
B.T1059
C.T1027
D.T1018
AnswerD

T1018 is the ID for Remote System Discovery which covers querying for other systems on the network.

Why this answer

T1087 (Account Discovery) or specifically T1018 (Remote System Discovery) are used for reconnaissance; 'net view' is specifically linked to Remote System Discovery.

149
MCQmedium

An analyst is investigating potential persistence via WMI event subscriptions. Which WMI namespace should the hunter focus on for suspicious event consumers?

A.root\default
B.root\security
C.root\cimv2
D.root\subscription
AnswerD

This namespace is where malicious event subscriptions are defined and stored.

Why this answer

The root\subscription namespace stores the classes (EventFilter, EventConsumer, FilterToConsumerBinding) used to execute malicious payloads.

150
MCQmedium

You are identifying Indicators of Compromise (IOCs) for an ongoing APT campaign. Which of the following is considered a Host-based IOC?

A.Registry key modification
B.User-Agent string in HTTP header
C.Domain name for C2 beaconing
D.Source IP address in firewall logs
AnswerA

Registry modifications are evidence of changes made on the host system.

Why this answer

A Registry key modification is a change made directly to the infected host system, making it a host-based indicator.

Page 1

Page 2 of 3

Page 3

All pages