CAP Threat Intelligence & Analysis 2 — Questions and Answers
Question 1: Which threat intelligence sharing framework uses a structured language called STIX to represent cyber threat information?
- TAXII (Correct answer)
- MISP
- OpenIOC
- CybOX
Correct answer: TAXII
TAXII (Trusted Automated eXchange of Indicator Information) is the transport protocol used to share STIX-formatted threat intelligence.
Question 2: In the context of threat intelligence, what does the term 'TTPs' stand for?
- Tools, Techniques, and Processes
- Tactics, Techniques, and Procedures (Correct answer)
- Threats, Targets, and Priorities
- Types, Trends, and Patterns
Correct answer: Tactics, Techniques, and Procedures
TTPs stands for Tactics, Techniques, and Procedures — the behavioral patterns that describe how threat actors operate.
Question 3: A security analyst receives intelligence indicating that a known APT group is targeting organizations in your sector. At what intelligence level is this information MOST useful?
- Operational
- Strategic (Correct answer)
- Tactical
- Technical
Correct answer: Strategic
Strategic intelligence informs senior leadership about threat actors targeting specific sectors, helping guide risk decisions and resource allocation.
Question 4: Which MITRE framework specifically maps adversary behaviors to detection and mitigation techniques for enterprise environments?
- MITRE CVE
- MITRE ATT&CK (Correct answer)
- MITRE CAPEC
- MITRE CWE
Correct answer: MITRE ATT&CK
MITRE ATT&CK (Adversarial Tactics, Techniques & Common Knowledge) is the knowledge base mapping real-world adversary behaviors to defensive countermeasures.
Question 5: What is the primary purpose of an Indicator of Compromise (IOC)?
- To predict future attacks before they occur
- To identify evidence that a system has been breached (Correct answer)
- To block malicious network traffic in real time
- To classify vulnerabilities by severity
Correct answer: To identify evidence that a system has been breached
IOCs are forensic artifacts — such as file hashes, IP addresses, or domain names — that indicate a system may have been compromised.
Question 6: Which threat intelligence source provides the MOST timely information about zero-day vulnerabilities?
- Open source intelligence (OSINT)
- Information Sharing and Analysis Centers (ISACs)
- Commercial threat intelligence feeds (Correct answer)
- Dark web monitoring services
Correct answer: Commercial threat intelligence feeds
Commercial threat intelligence feeds often have dedicated research teams and first-mover access to zero-day discoveries through private researcher networks.
Question 7: During threat modeling, which element of the PASTA methodology represents the final stage where attack simulations are performed?
- Stage V: Vulnerability analysis
- Stage VI: Attack enumeration
- Stage VII: Risk and impact analysis (Correct answer)
- Stage IV: Threat analysis
Correct answer: Stage VII: Risk and impact analysis
PASTA Stage VII (Risk and Impact Analysis) synthesizes all previous stages to simulate attacks and quantify business impact, forming the basis for risk treatment decisions.
Which threat intelligence sharing framework uses a structured language called STIX to represent cyber threat information?