CREST CREST Threat Intelligence & Risk Assessment 1 — Questions and Answers
Question 1: What is the MITRE ATT&CK framework primarily used for in threat intelligence?
- Scanning networks for open ports
- Cataloging adversary tactics, techniques, and procedures (TTPs) (Correct answer)
- Generating CVSS scores
- Automating patch management
Correct answer: Cataloging adversary tactics, techniques, and procedures (TTPs)
MITRE ATT&CK is a knowledge base of adversary TTPs observed in real-world attacks, used to improve detection, threat modeling, and red team planning.
Question 2: In threat intelligence, what does the Cyber Kill Chain model describe?
- The seven stages of a cyberattack from reconnaissance to actions on objectives (Correct answer)
- The lifecycle of a CVE from discovery to patch
- The NIST incident response phases
- The stages of malware reverse engineering
Correct answer: The seven stages of a cyberattack from reconnaissance to actions on objectives
Lockheed Martin's Cyber Kill Chain describes seven attack stages: Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command & Control, and Actions on Objectives.
Question 3: What is the primary purpose of a Threat Intelligence Platform (TIP) in a security operations context?
- Running automated penetration tests
- Aggregating, correlating, and operationalizing threat data from multiple sources (Correct answer)
- Managing vulnerability scan schedules
- Providing employee security awareness training
Correct answer: Aggregating, correlating, and operationalizing threat data from multiple sources
A TIP collects indicators of compromise (IoCs) and TTPs from multiple feeds, correlates them, and distributes actionable intelligence to security tools and analysts.
Question 4: Which threat intelligence category focuses on understanding adversary motivations, capabilities, and strategic intentions?
- Tactical intelligence
- Operational intelligence
- Strategic intelligence (Correct answer)
- Technical intelligence
Correct answer: Strategic intelligence
Strategic intelligence provides high-level insights about threat actor motivations, geopolitical factors, and long-term adversary campaigns intended for executive decision-making.
Question 5: What does a CVSS (Common Vulnerability Scoring System) base score measure?
- The business impact of a vulnerability specific to an organization
- The intrinsic severity of a vulnerability independent of environment (Correct answer)
- The likelihood that a vulnerability will be exploited in the next 30 days
- The cost to remediate a vulnerability
Correct answer: The intrinsic severity of a vulnerability independent of environment
The CVSS base score measures inherent vulnerability characteristics like attack vector, complexity, and impact, independent of time or deployment environment.
Question 6: In risk assessment, what is the formula for calculating risk?
- Risk = Threat × Asset Value
- Risk = Likelihood × Impact (Correct answer)
- Risk = Vulnerability ÷ Control
- Risk = Threat − Countermeasure
Correct answer: Risk = Likelihood × Impact
Risk is calculated as the product of the likelihood that a threat exploits a vulnerability and the resulting impact on the organization.
What is the MITRE ATT&CK framework primarily used for in threat intelligence?