FBI Criminal Intelligence and Investigations 2 — Questions and Answers
Question 1: What is the FBI's primary cyber threat intelligence mission?
- Investigating cyber intrusions, attribution of attacks, and disrupting nation-state and criminal cyber actors (Correct answer)
- Managing cybersecurity for all U.S. government networks
- Providing cyber threat intelligence exclusively to the private sector
- Conducting offensive cyber operations against adversaries
Correct answer: Investigating cyber intrusions, attribution of attacks, and disrupting nation-state and criminal cyber actors
The FBI leads federal domestic cyber threat investigation, combining intelligence analysis with law enforcement authority to investigate and disrupt cyber actors.
Question 2: What is 'ransomware' as a cyber threat the FBI investigates?
- Malicious software that encrypts victim data and demands payment for decryption keys (Correct answer)
- A phishing attack targeting senior government officials
- A denial-of-service attack against critical infrastructure
- Software that secretly harvests credentials from victim networks
Correct answer: Malicious software that encrypts victim data and demands payment for decryption keys
Ransomware is a category of malware that holds victim data hostage until a ransom is paid, often targeting hospitals, schools, and critical infrastructure.
Question 3: What does 'TTP' stand for in the context of FBI cyber intelligence?
- Tactics, Techniques, and Procedures used by cyber threat actors (Correct answer)
- Threat Tracking Protocol for cybercrime investigations
- Technical Threat Profile assigned to nation-state actors
- Targeted Threat Prevention program
Correct answer: Tactics, Techniques, and Procedures used by cyber threat actors
TTPs describe the behavioral patterns and methods used by threat actors, enabling attribution and the development of defensive countermeasures.
Question 4: What is 'attribution' in FBI cyber investigations?
- The process of identifying the responsible threat actor behind a cyber attack (Correct answer)
- Assigning jurisdiction between FBI and other agencies for a cyber case
- Classifying the severity of a cyber incident
- Linking malware samples to known criminal tools
Correct answer: The process of identifying the responsible threat actor behind a cyber attack
Attribution involves using technical indicators, tradecraft patterns, and intelligence to identify the nation-state or criminal group responsible for an attack.
Question 5: What is a 'watering hole attack' in the context of cyber threat intelligence?
- Compromising a website frequently visited by the target to infect visitors with malware (Correct answer)
- A denial-of-service attack that floods a network until it fails
- An attack that intercepts communications between two parties
- Sending malicious emails to all employees of a targeted organization
Correct answer: Compromising a website frequently visited by the target to infect visitors with malware
In a watering hole attack, adversaries compromise a legitimate website their targets commonly visit, using it as a vector to deliver malware.
Question 6: What is 'dark web' intelligence and why is it relevant to FBI investigations?
- Intelligence collected from encrypted, anonymized networks that host criminal marketplaces and forums (Correct answer)
- Classified FBI intelligence shared only within secure networks
- Intelligence gathered through technical surveillance of criminal communications
- Open-source intelligence derived from password-protected criminal forums
Correct answer: Intelligence collected from encrypted, anonymized networks that host criminal marketplaces and forums
The dark web hosts illicit marketplaces, criminal forums, and infrastructure that the FBI monitors to identify threat actors and gather investigative intelligence.
What is the FBI's primary cyber threat intelligence mission?