NEW
Font size
WorksheetsQuiz day 4
Total questions: 10
Worksheet time: 10mins
Kim, an analyst, is looking for an intelligence-sharing platform to gather and share threat information from a variety of sources. He wants to use this information to develop security policies to enhance the overall security posture of his organization.Which of the following sharing platforms should be used by Kim?
Blueliv threat exchange network
OmniPeek
Cuckoo sandbox
PortDroid network analysis
SecurityTech Inc. is developing a TI plan where it can drive more advantages in less funds. In the process of selecting a TI platform, it wants to incorporate a feature that ranks elements such as intelligence sources, threat actors, attacks, and digital assets of the organization, so that it can put in more funds toward the resources which are critical for the organization’s security. Which of the following key features should SecurityTech Inc. consider in their TI plan for selecting the TI platform?
Scoring
Search
Open
Workflow
An XYZ organization hired Mr. Andrews, a threat analyst. In order to identify the threats and mitigate the effect of such threats, Mr. Andrews was asked to perform threat modeling. During the process of threat modeling, he collected important information about the threat actor and characterized the analytic behavior of the adversary that includes technological details, goals, and motives that can be useful in building a strong countermeasure. What stage of the threat modeling is Mr. Andrews currently in
Threat profiling and attribution
System modeling
Threat ranking
Threat determination and identification
Miley, an analyst, wants to reduce the amount of collected data and make the storing and sharing process easy. She uses filtering, tagging, and queuing technique to sort out the relevant and structured data from the large amounts of unstructured data. Which of the following technique was employed by Miley?
Convenience sampling
Sandboxing
Data visualization
Normalization
Kathy wants to ensure that she shares threat intelligence containing sensitive information with the appropriate audience. Hence, she used traffic light protocol (TLP). Which TLP color would signify that information should be shared only within a particular community?
Red
Green
Amber
White
In which of the following attacks does the attacker exploit vulnerabilities in a computer application before the software developer can release a patch for them?
Advanced persistent attack
Active online attack
Zero-day attack
Distributed network attack
An analyst wants to disseminate the information effectively so that the consumers can acquire and benefit out of the intelligence. Which of the following criteria must an analyst consider in order to make the Intelligence must consist of good-quality content that provides the consumer an understanding of threats and their harmful consequences, which can help in developing a mitigation plan?
The right content
The right presentation
The right Time
The right order
There are some statements related to Information Exchange Types:
o Vulnerability advisories (e.g., reports consosting of additional context on attack scenarios and remediation methods)
o High-level alert data (e.g., alerts that require manual understanding)
o Trends and techniques of adversaries (e.g., detailed information on the behavior of malicious entity)
Based on the statement above, threat information can be categorized into?
Strategic Report
Adversories
Detection Indicators
Low-level Data
The following is one of the standard protocols used to exchange Cyber Threat Intelligence (CTI) information.
MRTI
STIX
TAXII
API
Which of the following statements is not suitable to describe TAXII?
is an application protocol for exchanging CTI over HTTPS
defines a RESTful API (a set of services and message exchanges)
specifically designed to support the exchange of CTI represented in STIX
is a language format used to exchange Cyber Threat Intelligence (CTI) information
