CSIA 105 UPDATED ACTUAL Exam
Questions and CORRECT Answers
An IOC occurs when what metric exceeds its normal bounds?
a. IRR
b. LRG
c. EXR
d. KRI - CORRECT ANSWER✔✔- d. KRI
What are the two concerns about using public information sharing centers?
a. Privacy and speed
b. Security and privacy
c. Regulatory approval and sharing
d. Cost and availability - CORRECT ANSWER✔✔- a. Privacy and speed
Which privacy protection uses four colors to indicate the expected sharing limitations that are
to be applied by recipients of the information?
a. PCII
b. TLP
c. CISA
d. FOIA - CORRECT ANSWER✔✔- b. TLP
Oskar has been receiving emails about critical threat intelligence information from a public
information sharing center. His team leader has asked him to look into how the process can
be automated so that the information can feed directly into their technology security. What
technology will Oskar recommend?
a. Bidirectional Security Protocol (BSP)
b. Linefeed Access
c. Lightwire JSON Control
d. Automated Indicator Sharing (AIS) - CORRECT ANSWER✔✔- d. Automated Indicator
Sharing (AIS)
, Which of the following is an application protocol for exchanging cyberthreat intelligence
over HTTPS?
a. STIX
b. TAXII
c. AIP-TAR
d. TCP-Over-Secure (ToP) - CORRECT ANSWER✔✔- b. TAXII
What are the two limitations of private information sharing centers?
a. Government approval and cost
b. Access to data and participation
c. Bandwidth and CPU
d. Timing of reports and remote access - CORRECT ANSWER✔✔- b. Access to data and
participation
Which of the following is NOT a limitation of a threat map?
a. Threat actors usually mask their real locations so what is displayed on a threat map is
incorrect.
b. Many maps claim that they show data in real time, but most are simply a playback of
previous attacks.
c. Because threat maps show anonymized data it is impossible to know the identity of the
attackers or the victims.
d. They can be difficult to visualize. - CORRECT ANSWER✔✔- d. They can be difficult to
visualize.
Luka has been asked by his supervisor to monitor the dark web for any IOCs concerning their
organization. The next week, Luca reports back that he was unable to find anything due to
how looking for information on the dark web is different from using the regular web. Which
of the following is not different about looking for information on the dark web?
a. Dark web merchants open and close their sites without warning.
b. It is necessary to use Tor or IP2.
c. Dark web search engines are identical to regular search engines.
d. The naming structure is different on the dark web. - CORRECT ANSWER✔✔- c. Dark
web search engines are identical to regular search engines.
Questions and CORRECT Answers
An IOC occurs when what metric exceeds its normal bounds?
a. IRR
b. LRG
c. EXR
d. KRI - CORRECT ANSWER✔✔- d. KRI
What are the two concerns about using public information sharing centers?
a. Privacy and speed
b. Security and privacy
c. Regulatory approval and sharing
d. Cost and availability - CORRECT ANSWER✔✔- a. Privacy and speed
Which privacy protection uses four colors to indicate the expected sharing limitations that are
to be applied by recipients of the information?
a. PCII
b. TLP
c. CISA
d. FOIA - CORRECT ANSWER✔✔- b. TLP
Oskar has been receiving emails about critical threat intelligence information from a public
information sharing center. His team leader has asked him to look into how the process can
be automated so that the information can feed directly into their technology security. What
technology will Oskar recommend?
a. Bidirectional Security Protocol (BSP)
b. Linefeed Access
c. Lightwire JSON Control
d. Automated Indicator Sharing (AIS) - CORRECT ANSWER✔✔- d. Automated Indicator
Sharing (AIS)
, Which of the following is an application protocol for exchanging cyberthreat intelligence
over HTTPS?
a. STIX
b. TAXII
c. AIP-TAR
d. TCP-Over-Secure (ToP) - CORRECT ANSWER✔✔- b. TAXII
What are the two limitations of private information sharing centers?
a. Government approval and cost
b. Access to data and participation
c. Bandwidth and CPU
d. Timing of reports and remote access - CORRECT ANSWER✔✔- b. Access to data and
participation
Which of the following is NOT a limitation of a threat map?
a. Threat actors usually mask their real locations so what is displayed on a threat map is
incorrect.
b. Many maps claim that they show data in real time, but most are simply a playback of
previous attacks.
c. Because threat maps show anonymized data it is impossible to know the identity of the
attackers or the victims.
d. They can be difficult to visualize. - CORRECT ANSWER✔✔- d. They can be difficult to
visualize.
Luka has been asked by his supervisor to monitor the dark web for any IOCs concerning their
organization. The next week, Luca reports back that he was unable to find anything due to
how looking for information on the dark web is different from using the regular web. Which
of the following is not different about looking for information on the dark web?
a. Dark web merchants open and close their sites without warning.
b. It is necessary to use Tor or IP2.
c. Dark web search engines are identical to regular search engines.
d. The naming structure is different on the dark web. - CORRECT ANSWER✔✔- c. Dark
web search engines are identical to regular search engines.