โ† All CCP Flashcard Decks

Cyber Threat Intelligence Lifecycle Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cyber Threat Intelligence Lifecycle flashcards as text
  1. Which CTI sharing standard is specifically designed to represent structured information about cyber threats and is commonly paired with TAXII for transport?

    Answer: STIX

    STIX (Structured Threat Information eXpression) is the standard format for representing CTI, and TAXII is the protocol used to transport STIX data between organizations.

  2. During the Collection phase, a CTI team leverages a commercial threat feed, dark web monitoring, and internal SIEM logs. This approach exemplifies which collection strategy?

    Answer: Multi-source collection

    Multi-source collection aggregates data from diverse internal and external sources to improve coverage and reduce blind spots in threat visibility.

  3. An analyst notices that a threat actor's TTPs closely match MITRE ATT&CK technique T1566 (Phishing). In which CTI lifecycle phase would this technique mapping most likely occur?

    Answer: Analysis

    Mapping observed behaviors to ATT&CK techniques is an analytical task performed during the Analysis phase to contextualize adversary actions.

  4. What is the primary risk of disseminating CTI products that contain outdated or expired indicators of compromise?

    Answer: Increased false positives and alert fatigue

    Expired IOCs generate false positives, eroding analyst trust in the intelligence program and consuming resources on non-existent threats.

  5. A threat intelligence platform (TIP) is most useful in which phase of the CTI lifecycle?

    Answer: Collection and Processing

    TIPs are primarily used during Collection to aggregate feeds and Processing to normalize, enrich, and deduplicate threat data before analysis.

  6. Which concept describes the practice of proactively searching for threats that have evaded automated detection, informed by CTI findings?

    Answer: Threat hunting

    Threat hunting uses CTI-derived hypotheses to proactively search environments for adversaries that have bypassed automated defenses.

  7. In the CTI lifecycle, which stakeholder group typically consumes strategic intelligence products?

    Answer: C-suite executives and board members

    Strategic intelligence addresses long-term trends, adversary motivations, and business risk, making it most relevant to executive and board-level decision-makers.