A financial services firm is building a new threat intelligence program. The CISO has requested a clear definition of the program's initial focus to secure executive buy-in. The primary goal is to proactively defend against threats targeting the firm's new mobile banking platform. Which of the following represents the MOST effective Priority Intelligence Requirement (PIR) for this initial phase?
Answer and explanation
Correct answer: C
A strong Priority Intelligence Requirement (PIR) is specific, actionable, and tied to a key organizational priority. This option is the most effective because it clearly defines the threat actors of interest (those targeting mobile banking apps), the geographic scope (EU and North America), the specific intelligence needed (TTPs and indicators), and directly supports the CISO's goal of protecting the new platform. The other options are too broad and not directly tied to the specific, high-priority asset.
Question 2
A threat analyst is using the Diamond Model of Intrusion Analysis to map out an attack campaign. The analyst has identified the victim (a healthcare provider), the adversary's infrastructure (a specific VPS provider), and the capability (a known PowerShell-based malware). The analyst now needs to pivot their investigation to uncover other related campaigns. Which meta-feature of the Diamond Model would be MOST useful for this purpose?
Answer and explanation
Correct answer: D
The Socio-Political meta-feature describes the adversary's intent and the victim's context (e.g., targeting healthcare during a pandemic). By understanding this context, the analyst can pivot to search for similar attacks against other healthcare providers or attacks motivated by the same geopolitical factors. This allows the analyst to link seemingly separate campaigns into a broader activity group, which is the goal of the pivot. The other options are less effective for expanding the investigation to other campaigns.
Question 3
A CTI team is automating the ingestion of threat indicators from various OSINT feeds using a Python script. They need to interact with the MISP API to add new attributes to existing events. The script has already authenticated and retrieved a specific event object. Which PyMISP function should the analyst use to add a new domain indicator to this event?
Answer and explanation
Correct answer: C
The misp.add_named_attribute() function is the correct choice. It allows an analyst to add an attribute to a specific event by providing the event object (or its ID) and the attribute's type and value (e.g., 'domain', 'evil.com'). misp.new_event() creates a completely new event. misp.add_attribute() is a lower-level function that requires a manually constructed attribute object. misp.update_event() is used for modifying event-level metadata, not for adding attributes.
Question 4
During an incident response, an analyst receives a sensitive piece of intelligence from a trusted partner in an ISAC. The intelligence contains indicators of compromise for an active campaign but also includes details about the partner's internal detection capabilities. The analyst needs to share the IoCs with their internal SOC team for immediate action but must not reveal the source's capabilities. What is this process of modifying the intelligence before dissemination called?
Answer and explanation
Correct answer: B
Sanitization is the process of removing sensitive information from intelligence products to protect sources, methods, or other confidential data before sharing it with a wider audience. In this scenario, the analyst is removing the partner's sensitive capabilities, which is a classic example of sanitization. Normalization is about formatting data consistently. Aggregation is combining data. Enrichment is adding context.
Question 5
Multiple answers
A threat intelligence team is investigating a series of attacks against their organization. They have collected data suggesting two possible culprits: APT-A, a known state-sponsored group, and FIN-B, a financially motivated cybercrime gang. The team lead decides to use the Analysis of Competing Hypotheses (ACH) to rigorously evaluate the evidence. Which of the following actions are critical steps in the ACH process that the team must perform? (Select THREE)
Answer and explanation
Correct answers: A, C, D
Question 6
Case Study
A multinational logistics company, ShipFast, has recently experienced a series of targeted attacks. Their CTI team, led by an experienced analyst named Maria, is tasked with building a comprehensive threat profile of the adversary. Initial intelligence suggests the attacker is a sophisticated group focused on supply chain disruption. The company uses a hybrid cloud environment, with critical shipping and tracking data stored in AWS S3 buckets and on-premises databases.
Maria's team has collected various pieces of data: malware samples from compromised endpoints, network logs showing connections to unusual IP addresses, and OSINT from social media mentioning disruptions to ShipFast's competitors. The CISO needs a strategic report on the threat actor's identity and long-term intentions, while the SOC needs tactical intelligence to improve detections immediately. The team has access to a MISP instance, a SIEM, and standard malware analysis tools.
To meet the CISO's needs, Maria's team must produce a strategic intelligence product. Which element is MOST crucial to include in this report for the CISO and executive board?
Answer and explanation
Correct answer: C
Strategic intelligence is forward-looking and focuses on high-level risks and business impact. For a CISO and executive board, the most critical information is not the technical minutiae but the 'so what?'—the adversary's goals, who they might be, and how their actions could affect the company's strategic objectives and standing in the market. This information drives decisions on security investment, risk management, and business strategy. The other options represent technical or tactical intelligence, which is vital for the SOC but not the primary focus for a strategic report.
Question 7
A threat hunter develops a hypothesis: 'An adversary is using WMI for lateral movement between workstations, evading our EDR's standard detections.' To test this, the hunter needs to search for specific event logs across the enterprise. Which Windows Event ID would be the MOST valuable to query for evidence of remote WMI command execution?
Answer and explanation
Correct answer: B
While several events can be related, Event ID 4688 is the most direct and valuable for this hypothesis. When WMI is used to execute a command remotely, the WMI Provider Host (WmiPrvSE.exe) on the target machine will spawn a new process to run that command. By filtering for Event ID 4688 where the parent process is WmiPrvSE.exe and the child process is something suspicious (like powershell.exe or cmd.exe), the hunter can directly find evidence supporting the hypothesis. Event 4624 is too general, 4776 relates to credential validation, and 5156 is for network connections.
Question 8
True or False: In the context of the Traffic Light Protocol (TLP), information designated as TLP:AMBER can be shared outside the recipient's organization without any restrictions.
Answer and explanation
Correct answer: B
This statement is false. TLP:AMBER indicates that information is limited to the recipient's organization and may only be shared with clients or customers who need to know in order to protect themselves or prevent further harm. It cannot be shared outside the organization without restrictions; any external sharing must be limited and purposeful.
Question 9
A CTI analyst needs to collect information about the infrastructure associated with a suspected malicious domain. The goal is to find subdomains, historical IP addresses, and related SSL certificate information without directly interacting with the target domain. Which OSINT tool is specifically designed for this type of passive DNS and infrastructure analysis?
Answer and explanation
Correct answer: C
VirusTotal is the best tool for this task among the options. Its domain and IP address reports provide extensive passive DNS data, historical WHOIS information, resolutions, detected URLs, and related SSL certificate details. Nmap is an active scanner. Maltego is a visualization and link analysis tool that often uses data from sources like VirusTotal. Wireshark is a network protocol analyzer for capturing live traffic, not for historical infrastructure analysis.
Question 10
A CTI team is briefing the organization's risk management committee. The intelligence indicates a high likelihood of a specific APT group targeting their industry within the next quarter. How does this threat intelligence directly support the risk management process?
Answer and explanation
Correct answer: B
The core function of risk management is to identify, assess, and mitigate risks. A key formula is Risk = Likelihood x Impact. Threat intelligence provides evidence-based data that directly informs the 'Likelihood' component of this equation. By indicating a high probability of a specific threat, CTI allows the risk committee to move from a generic or assumed likelihood to a specific, data-driven one, resulting in a more accurate risk assessment and better-informed decisions on resource allocation for mitigation.