Exam Coverage
1. Threat Intelligence Fundamentals — intelligence lifecycle, strategic/operational/tactical
intelligence, requirements, indicators, context, confidence, and intelligence value.
2. Intelligence Analysis — analytic methods, hypotheses, sourcing, confidence, uncertainty,
cognitive bias, fallacies, assumptions, and structured analytical techniques.
3. OSINT and Campaign Analysis — public sources, collection planning, campaign profiling,
intrusion characteristics, timelines, infrastructure, and external intelligence.
4. Attribution — evidence-based attribution, competing hypotheses, infrastructure reuse,
tooling, behaviors, victimology, false flags, and confidence levels.
5. Collection and Data Sets — threat feeds, domains, IP addresses, TLS certificates, DNS,
WHOIS/RDAP, logs, forensic artifacts, and data quality.
6. Kill Chain, Diamond Model, and Courses of Action — intrusion mapping, adversary
capabilities, infrastructure, victims, events, and defensive response options.
7. Malware Intelligence — static and behavioral analysis, sandboxing, hashes, strings,
configuration extraction, malware infrastructure, and intelligence pivots.
8. Pivoting and Domain Analysis — relationships among domains, certificates, IPs, registrars,
passive DNS, hosting, subdomains, and linked infrastructure.
9. Intelligence Sharing and Reporting — STIX/TAXII concepts, intelligence products,
assessments, executive reporting, tactical dissemination, and information handling.
,10. Intelligence Application and Threat-Informed Defense — applying intelligence to detection,
hunting, prioritization, risk decisions, incident response, and defensive planning.
Questions
1. While investigating related intrusion activity, Which observation can be especially useful
when investigating whether several domains may share common infrastructure over time?
A. Historical DNS resolution
B. Current keyboard layout
C. Screen brightness
D. File compression ratio
Answer: A
Rationale: Historical DNS information can reveal infrastructure relationships that are no longer
visible from current records.
2. For an analyst working on an active investigation, A vulnerability is actively exploited by an
adversary targeting the organization's technology stack. How can threat intelligence improve
prioritization?
A. Connect exploitation evidence with organizational exposure
B. Treat every vulnerability equally
C. Ignore business context
D. Only examine vendor marketing
,Answer: A
Rationale: Threat intelligence can help prioritize vulnerabilities by connecting adversary activity
to the organization's actual exposure and risk.
3. For an analyst working on an active investigation, Which observation can be especially useful
when investigating whether several domains may share common infrastructure over time?
A. Historical DNS resolution
B. Current keyboard layout
C. Screen brightness
D. File compression ratio
Answer: A
Rationale: Historical DNS information can reveal infrastructure relationships that are no longer
visible from current records.
4. When reviewing collected evidence, Why is source reliability important when analysts
combine information from several intelligence feeds into one assessment?
A. Poor sources can weaken the assessment
B. Reliable sources eliminate uncertainty
C. Source reliability proves attribution
D. Source reliability replaces analysis
Answer: A
, Rationale: Source reliability affects how much confidence analysts should place in collected
information.
5. For an analyst working on an active investigation, A vulnerability is actively exploited by an
adversary targeting the organization's technology stack. How can threat intelligence improve
prioritization?
A. Connect exploitation evidence with organizational exposure
B. Treat every vulnerability equally
C. Ignore business context
D. Only examine vendor marketing
Answer: A
Rationale: Threat intelligence can help prioritize vulnerabilities by connecting adversary activity
to the organization's actual exposure and risk.
6. During a threat intelligence investigation, A malware sample is executed in a controlled
environment to observe files, processes, network connections, and registry changes. What
technique is being used?
A. Behavioral analysis
B. Password cracking
C. Certificate transparency
D. Social engineering