NEW
Font size
WorksheetsThreat Intelligence
Total questions: 14
Worksheet time: 7mins
Which of these statements is true regarding zero-day attacks?
Most malicious code is accounted for today
The CVE is months behind in identifying these vulnerabilities
All malware and exploits were a zero-day at one time or another
The "zero" refers to the threat level on a scale of 0-10
Web that can be accessible using special software that uses a randomized path to its destination. Merupakan definisi dari?
Darkint
Darkweb
Deepweb
Surfaceweb
During the process of threat intelligence analysis, John, a threat analyst, successfully extracted an indication of adversary’s information, such as information on specific indicators of compromise consumed SOC staff, and IR Teams. Identify the type of threat intelligence analysis is performed by John?
Tactical threat intelligence analysis
Operational threat intelligence analysis
Strategic threat intelligence analysis
Technical threat intelligence analysis
Which is the following tools to access darknet
Tor browser
VPN
Bing
Shodan
What type of threat agent has greater access to information assets than external threats?
Spy
Hacker
Employee
Which security term ensures data is not disclosed to unintended persons?
Availability
Confidentiality
Non-repudiation
What makes sophisticated attacks difficult to detect?
They use simple tools
They vary their behavior
They only target specific users
Individuals or Team employed by the government to penetrate and gain top-secret information and to damage information systems of other governments. What kind of the threat actor above?
Hacktivists
State-Sponsored Hackers
Organized Hackers
Insider Threat
Analyzed and interpreted information providing broader in-depth knowledge of the subject, that supports decision making and response actions. What kind of the definition above?
Information
Data
Operational Environment
Intelligence
Getting all the information from public source and any where that we can get in the internet is part of data collecting in
IMINT
HUMINT
SIGINT
OSINT
Threat intelligence lifecycle.
1) Collection
2) Analysis and Production
3) Planning and Direction
4) Processing and Exploitation
5) Dissemination and Integration
What is the correct sequence of steps involved in a threat intelligence lifecycle?
2), 4), 3), 1), 5)
3), 2), 1), 4), 5)
3), 1), 2), 4), 5)
3), 1), 4), 2), 5)
Explain the process of transferring evidence from one person to another in the chain of custody.
Storing the evidence in a random location without proper documentation
Leaving the evidence unsealed and exposed to potential contamination
Not keeping track of who has possession of the evidence
Documenting each person who has had possession of the evidence, including the date and time of transfer, and ensuring that the evidence is properly sealed and stored to maintain its integrity.
Why is documentation of evidence important in the chain of custody?
To maintain the integrity and reliability of the evidence
To confuse the investigators
To waste time and resources
To make the evidence look more important
What is the first step in the collection of evidence?
Collecting all the evidence at once
Taking photos of the evidence without documenting
Proper documentation of the scene and surroundings
Ignoring the scene and surroundings
