CAP Threat Intelligence & Analysis 3 — Questions and Answers
Question 1: A threat intelligence analyst is evaluating a report claiming a nation-state actor is using a specific malware family. Which factor MOST determines the credibility of this intelligence?
- The length and detail of the report
- The reputation and track record of the source (Correct answer)
- The number of technical indicators included
- Whether the malware has a known CVE
Correct answer: The reputation and track record of the source
Source credibility — based on historical accuracy, methodology, and independence — is the primary factor in evaluating the reliability of threat intelligence.
Question 2: What is 'threat hunting' in the context of a cybersecurity program?
- Automated blocking of known malicious IPs
- Proactive search for hidden threats that evade automated detection (Correct answer)
- Reviewing vendor security alerts and advisories
- Scanning for vulnerabilities using automated tools
Correct answer: Proactive search for hidden threats that evade automated detection
Threat hunting is a proactive, human-led process of iteratively searching through networks and systems to detect threats that automated tools have not flagged.
Question 3: Which kill chain phase involves the adversary researching and identifying targets before an attack?
- Weaponization
- Reconnaissance (Correct answer)
- Exploitation
- Command and Control
Correct answer: Reconnaissance
Reconnaissance is the first phase of the Lockheed Martin Cyber Kill Chain, where attackers gather information about their intended target.
Question 4: In threat intelligence, what does 'pivoting' refer to?
- Switching from offensive to defensive security posture
- Using one indicator to discover related indicators and infrastructure (Correct answer)
- Redirecting network traffic through a proxy
- Changing the attribution of an attack to a different threat actor
Correct answer: Using one indicator to discover related indicators and infrastructure
Pivoting is the analytical technique of using a known IOC (such as a domain or IP) to discover additional related infrastructure and indicators used by the same threat actor.
Question 5: Which type of threat actor is typically characterized by advanced capabilities, long dwell times, and nation-state sponsorship?
- Hacktivists
- Script kiddies
- Advanced Persistent Threats (APTs) (Correct answer)
- Cybercriminal groups
Correct answer: Advanced Persistent Threats (APTs)
APTs are sophisticated, well-funded threat actors — typically nation-state affiliated — that conduct long-term, targeted intrusion campaigns with persistence and stealth.
Question 6: What is the Diamond Model of Intrusion Analysis primarily used for?
- Calculating the financial impact of a cyberattack
- Structuring the analysis of adversary, capability, infrastructure, and victim relationships (Correct answer)
- Prioritizing vulnerability remediation based on CVSS scores
- Mapping network topology to identify attack paths
Correct answer: Structuring the analysis of adversary, capability, infrastructure, and victim relationships
The Diamond Model provides a framework for structuring intrusion analysis around four core features: adversary, capability, infrastructure, and victim.
Question 7: A CAP practitioner is reviewing threat intelligence to update a system's risk assessment. Which intelligence product would BEST support this activity?
- A raw malware sample from a threat actor
- A finished intelligence report with context and analysis (Correct answer)
- A list of IP addresses flagged by a SIEM
- Real-time firewall block logs
Correct answer: A finished intelligence report with context and analysis
Finished intelligence reports provide analyzed, contextualized information suitable for risk assessment decisions, unlike raw data that requires further analysis.
A threat intelligence analyst is evaluating a report claiming a nation-state actor is using a specific malware family.
Which factor MOST determines the credibility of this intelligence?