CREST Threat Intelligence & Analysis 2 — Questions and Answers
Question 1: What does the Cyber Kill Chain model describe?
- The stages of a cyberattack from reconnaissance through to the attacker achieving their objectives (Correct answer)
- The chain of custody for digital evidence
- The sequence of controls in a defense-in-depth model
- The lifecycle of a vulnerability from discovery to patch
Correct answer: The stages of a cyberattack from reconnaissance through to the attacker achieving their objectives
The Cyber Kill Chain, developed by Lockheed Martin, describes seven stages of a targeted attack: reconnaissance, weaponization, delivery, exploitation, installation, command-and-control, and actions on objectives.
Question 2: Which threat actor category is typically characterized by nation-state backing and long-term persistent access to targeted networks?
- Advanced Persistent Threat (APT) (Correct answer)
- Hacktivist
- Script kiddie
- Insider threat
Correct answer: Advanced Persistent Threat (APT)
APT groups are sophisticated, well-funded actors typically linked to nation-states who conduct long-term espionage or sabotage campaigns against high-value targets.
Question 3: What is OSINT (Open Source Intelligence) as used in security threat analysis?
- Intelligence gathered from publicly available sources such as social media, websites, and databases (Correct answer)
- Intelligence obtained from classified government databases
- Intelligence derived from intercepted network traffic
- Intelligence gathered during authorized penetration tests
Correct answer: Intelligence gathered from publicly available sources such as social media, websites, and databases
OSINT involves collecting and analyzing information from publicly accessible sources to support threat intelligence, attack surface mapping, and adversary profiling.
Question 4: What is the primary goal of threat hunting?
- Proactively searching for hidden threats that have evaded automated detection (Correct answer)
- Responding to confirmed security alerts
- Configuring SIEM correlation rules
- Conducting regular vulnerability scans
Correct answer: Proactively searching for hidden threats that have evaded automated detection
Threat hunting is a proactive, hypothesis-driven investigation of networks and systems to find adversaries who have bypassed automated detection controls.
Question 5: Which type of threat intelligence focuses on understanding the strategic motivations and goals of adversary groups?
- Strategic intelligence (Correct answer)
- Tactical intelligence
- Operational intelligence
- Technical intelligence
Correct answer: Strategic intelligence
Strategic intelligence provides high-level insight into threat actor motivations, geopolitical context, and long-term trends, informing executive-level security decisions.
Question 6: What is a threat feed in the context of security operations?
- A continuously updated stream of IoCs and threat data from external providers (Correct answer)
- An internal log of blocked firewall connections
- A list of approved software applications
- A schedule of planned penetration tests
Correct answer: A continuously updated stream of IoCs and threat data from external providers
A threat feed is a real-time or regularly updated data stream of IoCs, malicious IPs, domains, and hashes that security tools consume to detect known threats.
What does the Cyber Kill Chain model describe?