CSX Surveillance & Intelligence Gathering 3 â Questions and Answers
Question 1: An attacker uses LinkedIn to map reporting structures, employee roles, and technology stacks at a target organization. Which phase of the intelligence lifecycle does this represent?
- Dissemination
- Collection (Correct answer)
- Analysis
- Production
Correct answer: Collection
Harvesting information from social media and professional networks to feed into an intelligence assessment is a collection activity in the intelligence lifecycle.
Question 2: Which DNS record type, when misconfigured to allow unauthenticated queries, can reveal an organization's entire internal host list to an attacker?
- MX record
- AAAA record
- SOA record
- Zone transfer (AXFR) (Correct answer)
Correct answer: Zone transfer (AXFR)
An unrestricted DNS zone transfer (AXFR query) allows any requester to download all DNS records for a zone, exposing internal hostnames, IP addresses, and network topology.
Question 3: Maltego is primarily used by security practitioners for:
- Fuzzing web application inputs
- Visualizing relationships between entities during OSINT investigations (Correct answer)
- Brute-forcing authentication credentials
- Scanning networks for open ports
Correct answer: Visualizing relationships between entities during OSINT investigations
Maltego transforms raw OSINT data into graphical link charts that reveal relationships between people, domains, IP addresses, and organizations.
Question 4: What is 'traffic analysis' in the context of surveillance, even when communications are encrypted?
- Decrypting TLS sessions using captured private keys
- Inferring information from communication patterns such as timing, frequency, and endpoints (Correct answer)
- Injecting malicious packets into a data stream
- Filtering packets based on deep packet inspection rules
Correct answer: Inferring information from communication patterns such as timing, frequency, and endpoints
Traffic analysis derives intelligence from metadataâwho communicates with whom, how often, at what times, and how much data is exchangedâwithout decrypting the payload.
Question 5: Which term describes a curated set of adversary TTPs, infrastructure indicators, and attribution data collected from multiple intelligence sources about a specific threat actor?
- Vulnerability database
- Threat actor profile (Correct answer)
- Patch bulletin
- Asset inventory
Correct answer: Threat actor profile
A threat actor profile consolidates all available intelligence about a specific adversary group, including their motivations, capabilities, and historical TTPs, to support proactive defense.
Question 6: A security team shares machine-readable threat intelligence with partner organizations using a standardized format. Which pair of specifications is most commonly used for this purpose?
- SNMP and MIB
- STIX and TAXII (Correct answer)
- CEF and LEEF
- OpenIOC and YARA
Correct answer: STIX and TAXII
STIX (Structured Threat Information eXpression) defines the format for threat intelligence objects, while TAXII (Trusted Automated eXchange of Intelligence Information) defines the transport protocol for sharing them.
Question 7: An analyst observes that an adversary's C2 domain was registered 48 hours before the attack and hosted on a bulletproof hosting provider. This information is most useful for:
- Patching the exploited vulnerability
- Building detection rules based on attacker infrastructure patterns (Correct answer)
- Recovering encrypted files after ransomware infection
- Resetting compromised user passwords
Correct answer: Building detection rules based on attacker infrastructure patterns
Understanding infrastructure patternsâshort domain age and bulletproof hostingâallows defenders to create proactive detection signatures that identify similar future attacker infrastructure.
An attacker uses LinkedIn to map reporting structures, employee roles, and technology stacks at a target organization.
Which phase of the intelligence lifecycle does this represent?