CREST Threat Intelligence & Analysis 1 — Questions and Answers
Question 1: What is the primary purpose of Cyber Threat Intelligence (CTI)?
- To provide actionable information about threats that helps organizations make better security decisions (Correct answer)
- To perform automated vulnerability scanning
- To generate compliance reports for regulators
- To monitor employee activity on corporate networks
Correct answer: To provide actionable information about threats that helps organizations make better security decisions
CTI collects, processes, and analyzes threat data to produce actionable insights that help defenders prioritize and improve their security posture.
Question 2: Which of the following describes a Tactics, Techniques, and Procedures (TTP) in threat intelligence?
- The behavioral patterns of how threat actors plan and execute attacks (Correct answer)
- The list of known malware file hashes
- The IP addresses used by command-and-control servers
- The CVE identifiers for known vulnerabilities
Correct answer: The behavioral patterns of how threat actors plan and execute attacks
TTPs describe the methods and behaviors adversaries use, from high-level strategy (tactics) to specific implementation details (techniques and procedures).
Question 3: What is an Indicator of Compromise (IoC)?
- A piece of forensic evidence that suggests a system may have been breached (Correct answer)
- A warning that a system patch is overdue
- A security policy violation by an employee
- A vulnerability found during a penetration test
Correct answer: A piece of forensic evidence that suggests a system may have been breached
An IoC is observable evidence such as a malicious IP, domain, file hash, or registry key that indicates a system has likely been compromised.
Question 4: Which threat intelligence sharing standard uses a structured language to describe cyber threat information in a machine-readable format?
- STIX (Structured Threat Information eXpression) (Correct answer)
- CVSS
- OVAL
- SCAP
Correct answer: STIX (Structured Threat Information eXpression)
STIX is a standardized language for describing CTI content in a structured, machine-readable way that enables automated sharing and analysis of threat data.
Question 5: What is the Diamond Model of Intrusion Analysis used for?
- Analyzing intrusions by mapping relationships between adversary, capability, infrastructure, and victim (Correct answer)
- Visualizing network traffic flows during an attack
- Scoring vulnerabilities based on exploitability
- Categorizing malware families by behavior
Correct answer: Analyzing intrusions by mapping relationships between adversary, capability, infrastructure, and victim
The Diamond Model provides a framework for understanding intrusions by examining the four core features — adversary, capability, infrastructure, and victim — and their relationships.
Question 6: Which concept in threat intelligence describes the relative difficulty for defenders to detect and respond to different types of indicators?
- The Pyramid of Pain (Correct answer)
- The Kill Chain
- The Diamond Model
- ATT&CK Navigator
Correct answer: The Pyramid of Pain
The Pyramid of Pain ranks IoC types by how painful it is for attackers if defenders detect and block them, from easy-to-change IPs at the bottom to hard-to-change TTPs at the top.
What is the primary purpose of Cyber Threat Intelligence (CTI)?