SANS FOR 578 -GIAC GCTI CERT EXAM PREP
GRADED A+
Correct
Incorrect
1 of 200
Term
While analyzing an attempted intrusion to a network, starting with a
beacon to a C2 node, what stage should be revisited in order to push
back the kill chain?
Give this one a try later!
Stage 7 (Actions on Objectives) - Stage 1 (Reconnaissance) -
determining the final impact of the understanding the attacker's initial
attack. goals.
Stage 5 (Install) - indicators can
be used to push back the kill Stage 3 (Exploitation) - analyzing the
chain and reveal new indicators vulnerability that was used.
to help mitigate intrusions.
, Don't know?
2 of 200
Term
What is middle ground?
Give this one a try later!
Adhering strictly to one extreme
Ignoring data that does not fit the
viewpoint without considering
initial hypothesis
alternatives
Making a compromise between
Rejecting all evidence that
two points and an accepted
contradicts a pre-existing belief
truth
Don't know?
3 of 200
Term
Why might external reports be useful?
Give this one a try later!
, They provide a complete history of They are always more accurate than
every cyber attack ever recorded internal analysis
They can fill in gaps in your They eliminate the need for
analysis independent analysis
Don't know?
4 of 200
Term
What command format can be used to pull STIX objects from a TAXII2
server?
Requests.get(URL)
Collection(URL)
urllib.urlopen(URL).read()
urllib2(URL).read()
Give this one a try later!
A flaw in reason Collection(URL)
Similar naming convention as
Know your audience
legitimate services
Don't know?
, 5 of 200
Term
Name some don'ts when it comes to naming campaigns
Give this one a try later!
Anchoring Active - last seen in last 6 months
Confirmation Bias Inactive - no linked intrusion for more
Congruence Bias than 6 months
Hindsight Bias Dormant - no linked intrusion in a
Illusory Correlation year
Dont Name campaign after
tool/TTP
Potentially requires personal
Dont Use enumerated names
information of the attacker to sign up
Dont Use an attribution scheme
May lead to a money trail
Dont Name campaign after
incident
Don't know?
6 of 200
Term
On the sliding scale of cyber security, what category to analysts
respond to and learn from adversaries on their network?
Give this one a try later!
GRADED A+
Correct
Incorrect
1 of 200
Term
While analyzing an attempted intrusion to a network, starting with a
beacon to a C2 node, what stage should be revisited in order to push
back the kill chain?
Give this one a try later!
Stage 7 (Actions on Objectives) - Stage 1 (Reconnaissance) -
determining the final impact of the understanding the attacker's initial
attack. goals.
Stage 5 (Install) - indicators can
be used to push back the kill Stage 3 (Exploitation) - analyzing the
chain and reveal new indicators vulnerability that was used.
to help mitigate intrusions.
, Don't know?
2 of 200
Term
What is middle ground?
Give this one a try later!
Adhering strictly to one extreme
Ignoring data that does not fit the
viewpoint without considering
initial hypothesis
alternatives
Making a compromise between
Rejecting all evidence that
two points and an accepted
contradicts a pre-existing belief
truth
Don't know?
3 of 200
Term
Why might external reports be useful?
Give this one a try later!
, They provide a complete history of They are always more accurate than
every cyber attack ever recorded internal analysis
They can fill in gaps in your They eliminate the need for
analysis independent analysis
Don't know?
4 of 200
Term
What command format can be used to pull STIX objects from a TAXII2
server?
Requests.get(URL)
Collection(URL)
urllib.urlopen(URL).read()
urllib2(URL).read()
Give this one a try later!
A flaw in reason Collection(URL)
Similar naming convention as
Know your audience
legitimate services
Don't know?
, 5 of 200
Term
Name some don'ts when it comes to naming campaigns
Give this one a try later!
Anchoring Active - last seen in last 6 months
Confirmation Bias Inactive - no linked intrusion for more
Congruence Bias than 6 months
Hindsight Bias Dormant - no linked intrusion in a
Illusory Correlation year
Dont Name campaign after
tool/TTP
Potentially requires personal
Dont Use enumerated names
information of the attacker to sign up
Dont Use an attribution scheme
May lead to a money trail
Dont Name campaign after
incident
Don't know?
6 of 200
Term
On the sliding scale of cyber security, what category to analysts
respond to and learn from adversaries on their network?
Give this one a try later!