CySA+ Test Threat Intelligence 3 — Questions and Answers
Question 1: Which confidence scoring model is commonly used in threat intelligence reports to express the analyst's certainty about an assessment?
- CVSS scoring
- Admiralty Code / Probabilistic language scale (Correct answer)
- DREAD model
- OWASP Risk Rating
Correct answer: Admiralty Code / Probabilistic language scale
The Admiralty Code (source reliability + information credibility) and NATO/probabilistic language scales are standard ways to express confidence in intelligence assessments.
Question 2: A security team wants to understand the motivations and long-term goals of a threat actor. Which intelligence tier best addresses this need?
- Technical intelligence
- Tactical intelligence
- Operational intelligence
- Strategic intelligence (Correct answer)
Correct answer: Strategic intelligence
Strategic intelligence addresses high-level adversary motivations, geopolitical context, and long-term trends for executive and policy decision-making.
Question 3: Which TAXII collection type allows a client to both push and pull threat intelligence from a server?
- Channel
- Collection (Correct answer)
- Feed
- Bundle
Correct answer: Collection
In TAXII 2.x, a Collection is an interface for sharing STIX objects where clients can query (pull) and optionally push intelligence.
Question 4: An analyst discovers that an IOC flagged in their SIEM was published three years ago and has not appeared in any recent feeds. How should the analyst treat this IOC?
- Immediately escalate as a critical incident
- Treat it as high confidence because it has been validated over time
- Consider it potentially stale and verify its current relevance (Correct answer)
- Remove it from the SIEM permanently
Correct answer: Consider it potentially stale and verify its current relevance
IOCs have a limited lifespan; old indicators may represent infrastructure no longer used by adversaries, requiring freshness validation before acting on them.
Question 5: Which threat actor category is typically motivated by financial gain and operates using ransomware-as-a-service (RaaS) models?
- Nation-state actor
- Hacktivist
- Cybercriminal (Correct answer)
- Insider threat
Correct answer: Cybercriminal
Cybercriminals, particularly organized crime groups, commonly monetize attacks through ransomware-as-a-service affiliate programs.
Question 6: What is the key difference between a threat feed and threat intelligence?
- Threat feeds are always paid; threat intelligence is free
- Threat feeds provide raw data; threat intelligence adds analysis and context (Correct answer)
- Threat intelligence only covers nation-state actors
- Threat feeds are structured in STIX; intelligence uses plain text
Correct answer: Threat feeds provide raw data; threat intelligence adds analysis and context
Threat feeds deliver raw IOC data, while threat intelligence involves processing, analyzing, and contextualizing that data to support decision-making.
Question 7: A CISO requests a briefing on how a recent APT campaign may affect the organization's industry vertical. Which intelligence product best fulfills this request?
- A blocklist of malicious IPs
- A YARA rule set for detection
- A strategic threat intelligence report (Correct answer)
- A STIX bundle of campaign IOCs
Correct answer: A strategic threat intelligence report
A strategic threat intelligence report contextualizes adversary campaigns within industry trends and provides actionable insights for executive decision-making.
Which confidence scoring model is commonly used in threat intelligence reports to express the analyst's certainty about an assessment?