312-85: Certified Threat Intelligence Analyst Practice Exam
QuestionQ1
Cyber Threats and Kill Chain Methodology
Save question
Lizzy, an analyst, wants to identify the organization’s risk levels in order to plan countermeasures against cyberattacks. She used a threat-modelling methodology that involved these stages:
Stage 1: Build asset-based threat profiles
Stage 2: Identify infrastructure vulnerabilities
Stage 3: Develop security strategy and plans
Which threat-modelling methodology did Lizzy use in the scenario described?
ATRIKE
BVAST
COCTAVE
DDREAD
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ2
Data Collection and Processing
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ3
Intelligence Reporting and Dissemination
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ4
Data Collection and Processing
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ5
Data Analysis
0
Community Discussion
No comments yet. Be the first to start the discussion!
It's free
100% of the questions are free for all users. No strings attached.
Introduction to Threat IntelligenceCyber Threats and Kill Chain MethodologyRequirements, Planning, Direction, and ReviewData Collection and ProcessingData AnalysisIntelligence Reporting and Dissemination
Tyrion, a professional hacker, is targeting an organization to steal confidential information. He wants to conduct website footprinting to obtain the following information, which is concealed in the web page header:
Connection status and content type
Accept-ranges and last-modified information
X-powered-by information
The web server being used and its version
Which of the following tools should Tyrion use to view the header content?
AHydra
BAutoShun
CVanguard enforcer
DBurp suite
Mario works as an analyst for an XYZ organization in the United States. He has been asked to prepare a threat landscape report that provides in-depth awareness and greater insight into the threats facing his organization.
Which of the following details should she include when preparing a threat landscape report?
AHistory of an attack and location where it was performed
BAttacker’s motivation and intention behind the attack
CAttribution of an attack to specific threat actor or group
DA summary of threat actors most likely targeting the organization along with their motivations, intentions, and TTPs.
Alison, an analyst at an XYZ organization, wants to retrieve information about a company’s website from its inception, including information that has been removed from the target website.
What should Alison do to obtain the information needed?
AAlison should use SmartWhois to extract the required website information.
BAlison should use https://archive.org to extract the required website information.
CAlison should run the Web Data Extractor tool to extract the required website information.
DAlison should recover cached pages of the website from the Google search engine cache to extract the required website information.
Walter and Sons Company has experienced major cyberattacks and the loss of confidential data. The company has decided to focus more on security than on other resources. Therefore, it hired Alice, a threat analyst, to perform data analysis. Alice was asked to conduct qualitative data analysis to extract useful information from collected bulk data.
Which of the following techniques would help Alice perform qualitative data analysis?
ARegression analysis, variance analysis, and so on
BNumerical calculations, statistical modeling, measurement, research, and so on.
CBrainstorming, interviewing, SWOT analysis, Delphi technique, and so on
DFinding links between data and discover threat-related information
QuestionQ6
Introduction to Threat Intelligence
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Cyber Threats and Kill Chain Methodology
QuestionQ8
Data Collection and Processing
QuestionQ9
Data Analysis
QuestionQ10
Data Analysis
QuestionQ11
Data Analysis
QuestionQ12
Requirements, Planning, Direction, and Review
QuestionQ13
Cyber Threats and Kill Chain Methodology
QuestionQ14
Intelligence Reporting and Dissemination
QuestionQ15
Data Analysis
QuestionQ16
Data Analysis
QuestionQ17
Requirements, Planning, Direction, and Review
QuestionQ18
Introduction to Threat Intelligence
QuestionQ19
Requirements, Planning, Direction, and Review
QuestionQ20
Data Collection and Processing
QuestionQ21
Cyber Threats and Kill Chain Methodology
QuestionQ22
Data Analysis
QuestionQ23
Data Collection and Processing
QuestionQ24
Requirements, Planning, Direction, and Review
QuestionQ25
Data Collection and Processing
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
ABC is a well-established cybersecurity company in the United States. The organization has automated tasks such as data enrichment and indicator aggregation. It has also joined various communities to expand its knowledge of emerging threats. However, the security teams can detect and prevent only identified threats through a reactive approach.
Based on the threat intelligence maturity model, identify ABC's level to determine the stage at which the organization stands regarding its security and vulnerabilities.
ALevel 2: increasing CTI capabilities
BLevel 3: CTI program in place
CLevel 1: preparing for CTI
DLevel 0: vague where to start
Which of the following attacks involves an attacker exploiting vulnerabilities in a computer application before the software developer is able to release a patch?
AActive online attack
BZero-day attack
CDistributed network attack
DAdvanced persistent attack
Jian is a member of the security team at Trinity, Inc. He is conducting a real-time assessment of system activities to acquire threat intelligence feeds. He obtains feeds from sources such as honeynets, P2P monitoring infrastructure, and application logs.
Which category of threat intelligence feed did Jian acquire?
AInternal intelligence feeds
BExternal intelligence feeds
CCSV data feeds
DProactive surveillance feeds
A team of threat-intelligence analysts is conducting malware threat analysis, and each analyst has developed a theory and evidence supporting that theory for a particular malware sample.
To identify the theory that is most consistent among all the theories, which analytic process must the threat intelligence manager use?
AThreat modelling
BApplication decomposition and analysis (ADA)
CAnalysis of competing hypotheses (ACH)
DAutomated technical analysis
Which type of threat attribution involves identifying the specific person, society, or country that sponsors a carefully planned and executed intrusion or attack against its target?
ANation-state attribution
BTrue attribution
CCampaign attribution
DIntrusion-set attribution
During threat intelligence analysis, John, a threat analyst, successfully extracted information about an adversary, such as its modus operandi, tools, communication channels, and forensic-evasion strategies.
Identify the type of threat intelligence analysis John performed.
AOperational threat intelligence analysis
BTechnical threat intelligence analysis
CStrategic threat intelligence analysis
DTactical threat intelligence analysis
Kira is a security analyst in an organization. She has been asked to define and establish requirements before collecting threat intelligence information. The requirements should concentrate on what must be gathered to fulfill production intelligence.
Which category of threat intelligence requirements should Kira focus on?
AProduction requirements
BBusiness requirements
CCollection requirements
DIntelligence requirements
Jacob, a professional hacker, made an exact copy of an online shopping website. He copied all content from the original site to a local system, enabling him to build a dummy spam website for social-engineering attacks against employees.
Which technique did Jacob use to clone the website?
AData sampling
BSocial engineering
CTailgating
DWebsite mirroring
Kathy wants to ensure she shares threat intelligence containing sensitive information with the appropriate audience. Therefore, she used the Traffic Light Protocol (TLP).
Which TLP color indicates that information should be shared only within a particular community?
ARed
BWhite
CGreen
DAmber
You are a cybersecurity analyst at a financial institution. An unusual pattern of financial transactions has been detected, indicating possible fraud or money laundering. What specific type of threat intelligence would you use to analyze these financial activities and identify potential risks?
ATECHINT
BCHIS
CSOCINT
DFININT
Within a team of threat analysts, two people competed to project their respective hypotheses about given malware. To identify logical proof supporting those hypotheses, the threat intelligence manager applied a de-biasing strategy involving the study of strategic decision-making in situations with multistep interactions among numerous representatives, with or without perfect relevant information.
Which de-biasing strategy did the threat intelligence manager use to validate their hypotheses?
AGame theory
BMachine learning
CDecision theory
DCognitive psychology
John, a threat intelligence analyst at Cybertech Company, was asked to obtain information that gives greater insight into the current cyber risks. To gather this information, John needs to answer the following questions:
Why might the organization be attacked?
How might the organization be attacked?
Who might the intruders be?
Identify the type of security testing John is going to perform.
AWhite box testing
BBlack box testing
CIntelligence-led security testing
DPerformance testing
Alice, an analyst, shared information with security operations managers and network operations center (NOC) staff to protect organizational resources from various threats. The information Alice shared was highly technical and included threat-actor TTPs, malware campaigns, tools used by threat actors, and so on.
Which type of threat intelligence did Alice share?
AStrategic threat intelligence
BTactical threat intelligence
CTechnical threat intelligence
DOperational threat intelligence
Which sequence of steps is correct for scheduling a threat intelligence program?
Review the project charter
Identify all deliverables
Identify the sequence of activities
Identify task dependencies
Develop the final schedule
Estimate the duration of each activity
Identify and estimate resources for all activities
Define all activities
Build a work breakdown structure (WBS)
A1-->9-->2-->8-->3-->7-->4-->6-->5
B3-->4-->5-->2-->1-->9-->8-->7-->6
C1-->2-->3-->4-->5-->6-->9-->8-->7
D1-->2-->3-->4-->5-->6-->7-->8-->9
Enrage Tech Company hired Enrique, a security analyst, to perform threat-intelligence analysis. During the data-collection process, he used a counterintelligence mechanism in which a recursive DNS server performs interserver DNS communication. When any name server generates a request to the recursive DNS server, the recursive DNS servers log the received responses. The logged data is then replicated and stored in a central database. Using these logs, he analyzed malicious attempts occurring across the DNS infrastructure.
Which cyber counterintelligence (CCI) gathering technique did Enrique use for data collection?
AData collection through passive DNS monitoring
BData collection through DNS interrogation
CData collection through DNS zone transfer
DData collection through dynamic DNS (DDNS)
An attacker directs bots to use a camouflage mechanism that conceals phishing and malware-delivery locations within a rapidly changing network of compromised bots. In this technique, one domain name is associated with multiple IP addresses.
Which technique does the attacker use?
ADNS zone transfer
BDynamic DNS
CDNS interrogation
DFast-Flux DNS
SecurityTech Inc. is developing a TI plan to achieve more benefits with less funding. While selecting a TI platform, it wants to include a feature that ranks elements such as intelligence sources, threat actors, attacks, and the organization’s digital assets, so it can allocate more funds to resources that are critical to the organization’s security.
Which of the following key features should SecurityTech Inc. consider in its TI plan when selecting the TI platform?
ASearch
BOpen
CWorkflow
DScoring
Karry, a threat analyst at an XYZ organization, is conducting threat intelligence analysis. During the data-collection phase, he used a collection method involving no participants and based solely on analyzing and observing activities and processes occurring within the organization’s local boundaries.
Identify the type of data collection method Karry used.
AActive data collection
BPassive data collection
CExploited data collection
DRaw data collection
James, a senior threat intelligence officer, was assigned to assess the success and failure of the organization’s established threat intelligence program. As part of this assessment, James reviewed the intelligence program’s outcomes, determined whether the program required any improvements, and identified past learnings that could be applied to future programs.
Identify the activity James performed in this scenario.
ADetermine the costs and benefits associated with the program
BDetermine the fulfillment of stakeholders
CReport findings and recommendations
DConduct a gap analysis
A consortium was formed through a collaborative effort to improve the cybersecurity posture of several organizations in an industry sector. The participating organizations chose a threat-intelligence exchange architecture in which all threat data is gathered, analyzed, and distributed through one central hub. What type of threat-intelligence exchange architecture was implemented in this scenario?
Community Discussion