โ† All CySA+ Test Flashcard Decks

Threat Intelligence Flashcards

7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Threat Intelligence flashcards as text
  1. Which confidence scoring model is commonly used in threat intelligence reports to express the analyst's certainty about an assessment?

    Answer: Admiralty Code / Probabilistic language scale

    The Admiralty Code (source reliability + information credibility) and NATO/probabilistic language scales are standard ways to express confidence in intelligence assessments.

  2. A security team wants to understand the motivations and long-term goals of a threat actor. Which intelligence tier best addresses this need?

    Answer: Strategic intelligence

    Strategic intelligence addresses high-level adversary motivations, geopolitical context, and long-term trends for executive and policy decision-making.

  3. Which TAXII collection type allows a client to both push and pull threat intelligence from a server?

    Answer: Collection

    In TAXII 2.x, a Collection is an interface for sharing STIX objects where clients can query (pull) and optionally push intelligence.

  4. An analyst discovers that an IOC flagged in their SIEM was published three years ago and has not appeared in any recent feeds. How should the analyst treat this IOC?

    Answer: Consider it potentially stale and verify its current relevance

    IOCs have a limited lifespan; old indicators may represent infrastructure no longer used by adversaries, requiring freshness validation before acting on them.

  5. Which threat actor category is typically motivated by financial gain and operates using ransomware-as-a-service (RaaS) models?

    Answer: Cybercriminal

    Cybercriminals, particularly organized crime groups, commonly monetize attacks through ransomware-as-a-service affiliate programs.

  6. What is the key difference between a threat feed and threat intelligence?

    Answer: Threat feeds provide raw data; threat intelligence adds analysis and context

    Threat feeds deliver raw IOC data, while threat intelligence involves processing, analyzing, and contextualizing that data to support decision-making.

  7. A CISO requests a briefing on how a recent APT campaign may affect the organization's industry vertical. Which intelligence product best fulfills this request?

    Answer: A strategic threat intelligence report

    A strategic threat intelligence report contextualizes adversary campaigns within industry trends and provides actionable insights for executive decision-making.