CCP Cyber Threat Intelligence Lifecycle 2 — Questions and Answers
Question 1: During the 'Direction' phase of the CTI lifecycle, what is the primary output produced?
- Finished intelligence reports
- Intelligence requirements and collection priorities (Correct answer)
- Processed indicator feeds
- Dissemination schedules
Correct answer: Intelligence requirements and collection priorities
The Direction phase establishes intelligence requirements that guide what information will be collected and how resources are prioritized.
Question 2: A CTI analyst discovers that raw OSINT data contains significant noise and irrelevant information. Which lifecycle phase should address this problem?
- Direction
- Collection
- Processing (Correct answer)
- Dissemination
Correct answer: Processing
The Processing phase normalizes, filters, and structures raw collected data to remove noise and make it suitable for analysis.
Question 3: Which feedback mechanism in the CTI lifecycle ensures intelligence products remain aligned with stakeholder needs over time?
- Threat hunting reports
- Post-dissemination feedback loops (Correct answer)
- SIEM correlation rules
- Indicator expiration policies
Correct answer: Post-dissemination feedback loops
Post-dissemination feedback loops allow consumers to evaluate the intelligence's relevance and accuracy, informing future Direction phase decisions.
Question 4: An organization wants to understand the long-term strategic motivations of a nation-state adversary. Which type of intelligence should the CTI lifecycle produce?
- Operational intelligence
- Tactical intelligence
- Technical intelligence
- Strategic intelligence (Correct answer)
Correct answer: Strategic intelligence
Strategic intelligence addresses high-level adversary motivations, geopolitical context, and long-term trends to support executive decision-making.
Question 5: During the Analysis phase, a CTI team uses the Diamond Model to characterize an intrusion. Which four core features does this model relate?
- TTPs, IOCs, threat actors, and malware families
- Adversary, capability, infrastructure, and victim (Correct answer)
- Kill chain phase, tool, technique, and procedure
- Intent, opportunity, capability, and impact
Correct answer: Adversary, capability, infrastructure, and victim
The Diamond Model links adversary, capability, infrastructure, and victim as the four core features of any intrusion event.
Question 6: What distinguishes 'data' from 'intelligence' in the context of the CTI lifecycle?
- Data is classified; intelligence is unclassified
- Data is raw and unprocessed; intelligence is analyzed and contextualized (Correct answer)
- Data comes from OSINT; intelligence comes from HUMINT
- Data is machine-readable; intelligence is human-readable only
Correct answer: Data is raw and unprocessed; intelligence is analyzed and contextualized
Intelligence is the product of analyzing and contextualizing raw data to produce actionable insights, whereas data alone lacks meaning without processing.
Question 7: A CTI team is tasked with producing indicators to block active phishing campaigns within 24 hours. Which intelligence type best fits this requirement?
- Strategic intelligence
- Operational intelligence
- Tactical intelligence (Correct answer)
- Geopolitical intelligence
Correct answer: Tactical intelligence
Tactical intelligence provides near-real-time indicators of compromise (IOCs) such as IPs, domains, and hashes that defenders can act on immediately.
During the 'Direction' phase of the CTI lifecycle, what is the primary output produced?