wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Quiz day 4

Total questions: 10

Worksheet time: 10mins

Name
Class
Date
1.

Kim, an analyst, is looking for an intelligence-sharing platform to gather and share threat information from a variety of sources. He wants to use this information to develop security policies to enhance the overall security posture of his organization.Which of the following sharing platforms should be used by Kim?

a)

Blueliv threat exchange network

b)

OmniPeek

c)

Cuckoo sandbox

d)

PortDroid network analysis

2.

SecurityTech Inc. is developing a TI plan where it can drive more advantages in less funds. In the process of selecting a TI platform, it wants to incorporate a feature that ranks elements such as intelligence sources, threat actors, attacks, and digital assets of the organization, so that it can put in more funds toward the resources which are critical for the organization’s security. Which of the following key features should SecurityTech Inc. consider in their TI plan for selecting the TI platform?

a)

Scoring

b)

Search

c)

Open

d)

Workflow

3.

An XYZ organization hired Mr. Andrews, a threat analyst. In order to identify the threats and mitigate the effect of such threats, Mr. Andrews was asked to perform threat modeling. During the process of threat modeling, he collected important information about the threat actor and characterized the analytic behavior of the adversary that includes technological details, goals, and motives that can be useful in building a strong countermeasure. What stage of the threat modeling is Mr. Andrews currently in

a)

Threat profiling and attribution

b)

System modeling

c)

Threat ranking

d)

Threat determination and identification

4.

Miley, an analyst, wants to reduce the amount of collected data and make the storing and sharing process easy. She uses filtering, tagging, and queuing technique to sort out the relevant and structured data from the large amounts of unstructured data. Which of the following technique was employed by Miley?

a)

Convenience sampling

b)

Sandboxing

c)

Data visualization

d)

Normalization

5.

Kathy wants to ensure that she shares threat intelligence containing sensitive information with the appropriate audience. Hence, she used traffic light protocol (TLP). Which TLP color would signify that information should be shared only within a particular community?

a)

Red

b)

Green

c)

Amber

d)

White

6.

In which of the following attacks does the attacker exploit vulnerabilities in a computer application before the software developer can release a patch for them?

a)

Advanced persistent attack

b)

Active online attack

c)

Zero-day attack

d)

Distributed network attack

7.

An analyst wants to disseminate the information effectively so that the consumers can acquire and benefit out of the intelligence. Which of the following criteria must an analyst consider in order to make the Intelligence must consist of good-quality content that provides the consumer an understanding of threats and their harmful consequences, which can help in developing a mitigation plan?

a)

The right content

b)

The right presentation

c)

The right Time

d)

The right order

8.

There are some statements related to Information Exchange Types:

o Vulnerability advisories (e.g., reports consosting of additional context on attack scenarios and remediation methods)

o High-level alert data (e.g., alerts that require manual understanding)

o Trends and techniques of adversaries (e.g., detailed information on the behavior of malicious entity)

Based on the statement above, threat information can be categorized into?

a)

Strategic Report

b)

Adversories

c)

Detection Indicators

d)

Low-level Data

9.

The following is one of the standard protocols used to exchange Cyber Threat Intelligence (CTI) information.

a)

MRTI

b)

STIX

c)

TAXII

d)

API

10.

Which of the following statements is not suitable to describe TAXII?

a)

is an application protocol for exchanging CTI over HTTPS

b)

defines a RESTful API (a set of services and message exchanges)

c)

specifically designed to support the exchange of CTI represented in STIX

d)

is a language format used to exchange Cyber Threat Intelligence (CTI) information