Loading course title...
Loading assessment title...
Connecting to LMS...
Progress: in progress
Assessment
1. Which statement best defines cyber threat intelligence?
A. Any alert generated by a security tool
B. A large list of indicators from a feed
C. Analyzed, contextual threat information that supports a security decision
D. Unreviewed rumors about active attackers
2. Why is raw data different from intelligence?
A. Raw data still needs context, analysis, confidence, and a decision need
B. Raw data is always more accurate than analysis
C. Raw data can only come from internal telemetry
D. Raw data should never be used in security operations
3. Which audience is most likely to need strategic threat intelligence?
A. A malware sandbox process
B. A SIEM parser
C. A packet capture tool
D. Leaders and risk owners making planning decisions
4. Which lifecycle stage should come before collection?
A. Dissemination
B. Requirements
C. Feedback
D. Formatting
5. What is a healthy collection discipline?
A. Collect every available source before asking a question
B. Ignore licensing and handling rules during urgent work
C. Choose sources that can answer the requirement and evaluate reliability
D. Treat every public report as confirmed
6. Why are TTPs often more durable than individual indicators?
A. They remove the need for detection engineering
B. They are always easier to block than IP addresses
C. They are only used for executive reporting
D. They describe behavior that may persist after infrastructure changes
7. What is MITRE ATT&CK commonly used for in CTI work?
A. Organizing adversary tactics and techniques with a shared language
B. Automatically proving attribution
C. Replacing analyst confidence statements
D. Granting permission to collect private data
8. Which wording is most appropriate when evidence supports a judgment but is not definitive?
A. Guaranteed
B. Confirmed without review
C. Likely, with stated confidence and assumptions
D. Impossible to assess
9. What do STIX and TAXII help support?
A. Launching simulated attacks
B. Structured representation and exchange of threat intelligence
C. Removing all handling restrictions
D. Replacing source evaluation
10. What does it mean to operationalize threat intelligence?
A. Store more reports in a portal
B. Forward all feeds to every employee
C. Avoid feedback from SOC and engineering teams
D. Turn intelligence into actions such as detections, hunts, prioritization, or response guidance
Submit Quiz
Previous