wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Threat Intelligence

Total questions: 14

Worksheet time: 7mins

Name
Class
Date
1.

Which of these statements is true regarding zero-day attacks?

a)

Most malicious code is accounted for today

b)

The CVE is months behind in identifying these vulnerabilities

c)

All malware and exploits were a zero-day at one time or another

d)

The "zero" refers to the threat level on a scale of 0-10

2.

Web that can be accessible using special software that uses a randomized path to its destination. Merupakan definisi dari?

a)

Darkint

b)

Darkweb

c)

Deepweb

d)

Surfaceweb

3.

During the process of threat intelligence analysis, John, a threat analyst, successfully extracted an indication of adversary’s information, such as information on specific indicators of compromise consumed SOC staff, and IR Teams. Identify the type of threat intelligence analysis is performed by John?

a)

Tactical threat intelligence analysis

b)

Operational threat intelligence analysis

c)

Strategic threat intelligence analysis

d)

Technical threat intelligence analysis

4.

Which is the following tools to access darknet

a)

Tor browser

b)

VPN

c)

Bing

d)

Shodan

5.

What type of threat agent has greater access to information assets than external threats?

a)

Spy

b)

Hacker

c)

Employee

6.

Which security term ensures data is not disclosed to unintended persons?

a)

Availability

b)

Confidentiality

c)

Non-repudiation

7.

What makes sophisticated attacks difficult to detect?

a)

They use simple tools

b)

They vary their behavior

c)

They only target specific users

8.

Individuals or Team employed by the government to penetrate and gain top-secret information and to damage information systems of other governments. What kind of the threat actor above?

a)

Hacktivists

b)

State-Sponsored Hackers

c)

Organized Hackers

d)

Insider Threat

9.

Analyzed and interpreted information providing broader in-depth knowledge of the subject, that supports decision making and response actions. What kind of the definition above?

a)

Information

b)

Data

c)

Operational Environment

d)

Intelligence

10.

Getting all the information from public source and any where that we can get in the internet is part of data collecting in

a)

IMINT

b)

HUMINT

c)

SIGINT

d)

OSINT

11.

Threat intelligence lifecycle.

1) Collection

2) Analysis and Production

3) Planning and Direction

4) Processing and Exploitation

5) Dissemination and Integration

What is the correct sequence of steps involved in a threat intelligence lifecycle?

a)

2), 4), 3), 1), 5)

b)

3), 2), 1), 4), 5)

c)

3), 1), 2), 4), 5)

d)

3), 1), 4), 2), 5)

12.

Explain the process of transferring evidence from one person to another in the chain of custody.

a)

Storing the evidence in a random location without proper documentation

b)

Leaving the evidence unsealed and exposed to potential contamination

c)

Not keeping track of who has possession of the evidence

d)

Documenting each person who has had possession of the evidence, including the date and time of transfer, and ensuring that the evidence is properly sealed and stored to maintain its integrity.

13.

Why is documentation of evidence important in the chain of custody?

a)

To maintain the integrity and reliability of the evidence

b)

To confuse the investigators

c)

To waste time and resources

d)

To make the evidence look more important

14.

What is the first step in the collection of evidence?

a)

Collecting all the evidence at once

b)

Taking photos of the evidence without documenting

c)

Proper documentation of the scene and surroundings

d)

Ignoring the scene and surroundings