← All CySA+ Test Flashcard Decks

Threat Intelligence Flashcards

7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Threat Intelligence flashcards as text
  1. Which threat intelligence concept describes the process of converting raw data into finished intelligence products through collection, processing, analysis, and dissemination?

    Answer: Intelligence cycle

    The intelligence cycle (direction, collection, processing, analysis, dissemination, feedback) is the foundational process for producing actionable threat intelligence.

  2. An organization subscribes to an ISAC for threat intelligence. What is the primary benefit of ISAC membership?

    Answer: Sector-specific threat sharing among trusted peers in the same industry

    ISACs (Information Sharing and Analysis Centers) provide sector-specific threat intelligence sharing among trusted organizations in the same industry vertical.

  3. A threat analyst observes that a malware sample beacons to its C2 server every 300 seconds with a ±30 second jitter. Why does jitter matter for detection?

    Answer: Jitter randomizes beacon intervals to evade time-based anomaly detection

    C2 beacon jitter introduces randomness in communication timing to evade detection systems that flag regular, predictable heartbeat patterns.

  4. Which framework specifically maps adversary behaviors to pre-ATT&CK stages, covering actions from reconnaissance through actions on objectives, and was developed by Lockheed Martin?

    Answer: Cyber Kill Chain

    The Cyber Kill Chain, developed by Lockheed Martin, defines seven stages of an attack from reconnaissance to actions on objectives.

  5. When performing indicator enrichment, an analyst queries a passive DNS database. What unique value does passive DNS provide?

    Answer: It reveals historical DNS resolutions, linking domains to past IP addresses

    Passive DNS databases store historical DNS resolution records, allowing analysts to pivot from a domain to past IPs or from an IP to domains it has hosted.

  6. A threat intelligence report assigns a TLP:RED marking to a document. What does this mean for handling and distribution?

    Answer: It is restricted to the named recipients only and must not be forwarded

    TLP:RED (Traffic Light Protocol) restricts information to named recipients only; it cannot be shared further without explicit permission from the originator.

  7. Which analytical technique involves hypothesizing alternative explanations for observed adversary behavior to avoid confirmation bias in threat intelligence analysis?

    Answer: Analysis of competing hypotheses (ACH)

    Analysis of Competing Hypotheses (ACH) systematically evaluates multiple explanations for observed evidence, reducing cognitive bias in intelligence assessments.