CCP Cyber Threat Intelligence Lifecycle 3 — Questions and Answers
Question 1: Which CTI sharing standard is specifically designed to represent structured information about cyber threats and is commonly paired with TAXII for transport?
- OpenIOC
- STIX (Correct answer)
- MISP
- CybOX
Correct answer: STIX
STIX (Structured Threat Information eXpression) is the standard format for representing CTI, and TAXII is the protocol used to transport STIX data between organizations.
Question 2: During the Collection phase, a CTI team leverages a commercial threat feed, dark web monitoring, and internal SIEM logs. This approach exemplifies which collection strategy?
- Single-source collection
- Multi-source collection (Correct answer)
- Passive collection only
- Human intelligence collection
Correct answer: Multi-source collection
Multi-source collection aggregates data from diverse internal and external sources to improve coverage and reduce blind spots in threat visibility.
Question 3: An analyst notices that a threat actor's TTPs closely match MITRE ATT&CK technique T1566 (Phishing). In which CTI lifecycle phase would this technique mapping most likely occur?
- Direction
- Collection
- Processing
- Analysis (Correct answer)
Correct answer: Analysis
Mapping observed behaviors to ATT&CK techniques is an analytical task performed during the Analysis phase to contextualize adversary actions.
Question 4: What is the primary risk of disseminating CTI products that contain outdated or expired indicators of compromise?
- Over-classification of threat data
- Increased false positives and alert fatigue (Correct answer)
- Violation of STIX version requirements
- Degraded TAXII transport performance
Correct answer: Increased false positives and alert fatigue
Expired IOCs generate false positives, eroding analyst trust in the intelligence program and consuming resources on non-existent threats.
Question 5: A threat intelligence platform (TIP) is most useful in which phase of the CTI lifecycle?
- Direction only
- Collection and Processing (Correct answer)
- Dissemination only
- Analysis and Production
Correct answer: Collection and Processing
TIPs are primarily used during Collection to aggregate feeds and Processing to normalize, enrich, and deduplicate threat data before analysis.
Question 6: Which concept describes the practice of proactively searching for threats that have evaded automated detection, informed by CTI findings?
- Threat modeling
- Red teaming
- Threat hunting (Correct answer)
- Vulnerability scanning
Correct answer: Threat hunting
Threat hunting uses CTI-derived hypotheses to proactively search environments for adversaries that have bypassed automated defenses.
Question 7: In the CTI lifecycle, which stakeholder group typically consumes strategic intelligence products?
- SOC analysts
- Incident responders
- C-suite executives and board members (Correct answer)
- Penetration testers
Correct answer: C-suite executives and board members
Strategic intelligence addresses long-term trends, adversary motivations, and business risk, making it most relevant to executive and board-level decision-makers.
Which CTI sharing standard is specifically designed to represent structured information about cyber threats and is commonly paired with TAXII for transport?