← All CySA+ Test Flashcard Decks

Threat Intelligence Flashcards

7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Threat Intelligence flashcards as text
  1. Which open-source platform is widely used for sharing and collaborating on threat intelligence within a community, supporting STIX/TAXII natively?

    Answer: MISP

    MISP (Malware Information Sharing Platform) is an open-source TIP designed for community-based sharing of threat intelligence with STIX/TAXII support.

  2. During threat hunting, an analyst uses the hypothesis: 'An adversary has established persistence using scheduled tasks.' Which ATT&CK technique should they investigate first?

    Answer: T1053 – Scheduled Task/Job

    T1053 (Scheduled Task/Job) directly maps to persistence via scheduled tasks and should be the starting point for this hypothesis.

  3. What is the purpose of a kill chain analysis in threat intelligence?

    Answer: To map attacker actions to stages in order to identify defensive intervention points

    Kill chain analysis maps adversary activities to sequential stages (e.g., Lockheed Martin Cyber Kill Chain), revealing where defenders can disrupt the attack.

  4. An analyst is evaluating a threat intelligence source that frequently reports on threats irrelevant to the organization's industry. Which intelligence characteristic is this source failing to meet?

    Answer: Relevance

    Relevance measures how applicable the intelligence is to the organization's specific environment, industry, and threat landscape.

  5. Which technique involves registering domains that are visually similar to legitimate domains to trick users, and is commonly tracked in threat intelligence?

    Answer: Typosquatting/homograph attack

    Typosquatting and homograph attacks use look-alike domains (e.g., 'paypa1.com' or Unicode lookalikes) to deceive users into visiting malicious sites.

  6. A threat intelligence analyst identifies that two separate intrusion sets share the same C2 infrastructure and tooling. What can be inferred from this overlap?

    Answer: The intrusion sets may be operated by the same threat actor or affiliate

    Shared infrastructure and tooling are strong indicators that intrusion sets may share an operator, be affiliated, or represent a common supply of tools from a single actor.

  7. What does the term 'threat actor TTP' stand for, and why is it more durable than IOCs for detection?

    Answer: Tactics, Techniques, and Procedures; TTPs change slowly compared to infrastructure IOCs

    TTPs (Tactics, Techniques, and Procedures) describe how adversaries operate and are far more stable than IOCs like IPs or domains, which adversaries rotate frequently.