SECURITY BLUE TEAM LEVEL 1 FINAL EXAM QUESTIONS AND
VERIFIED ANSWERS 100% GRADED TO PASS
Malware Sandboxing
the process of running a piece of malware in a contained environment, and closely monitoring exactly
what the software does
allows security teams to collect indicators of compromise
Threat Intelligence Lifecycle
1. Planning & Direction
determines what the scope is for this specific threat intelligence project
goals need to be set, and the stakeholders need to be clearly defined
2. Collection
team will go out and collect all of the data they need to achieve their end goal of creating actionable
intelligence
3. Processing
transform data collected into a clear and readable format so that it can be analyzed, typically by human
threat intelligence analysts
4. Analysis
a human process where processed information is turned into actionable intelligence that can be used
- whether to investigate a potential threat
- what actions to take immediately to block an attack
- how to strengthen security controls
- how much to invest in additional security resources
5. Dissemination
getting the finished intelligence output to the places it needs to go
can be SOC, fellow Threat Intelligence Analysts, and even the executive board
6. Feedback
Page 1 of 17
,understand your overall intelligence priorities and the requirements of the security teams that will be
consuming the threat intelligence
SIGNT (Signal intelligence)
involves the interception of radio signals and broadcast communications to gather intelligence
OSINT (Open Source Intelligence)
information that is gathered from public source
HUMINT (Human Intelligence)
information gathered from human sources, often gathered through
- in-person meetings
- debriefings personnel tasked with acquiring information through observation, document gathering, etc
GEOSINT (Geospatial Intelligence)
use of satellite imaging to monitor activities such as
- tracking individuals of interest
- structural reconnaissance
- military movement location and tracking
- monitoring natural disaster
Strategic Threat Intelligence
provides high-level, typically non-technical information that can be understood by anyone
used when presenting to executives and other decision-makers within an organization to aid with
decisions such as budget spending and policy review or creation
Operational Threat Intelligence
studying threat actors that might target the organization, in order to gain information about
- who they are
- their motivations
- their tactics, techniques, and procedures (TTPs)
Page 2 of 17
, Tactical Threat Intelligence
technical in nature and is of immediate value to an organization
shared in the form of indicators of compromise (IOCs) such as
- URLs
- domains
- email addresses
- file hashes
- IP addresses
Cyber Criminals
group includes hackers and crackers that are looking to make money from malicious and illegal activity,
such as
- cyber-attacks
- ransomware
- phishing
Nation-States/APTs
hackers or hacking teams that work for governments around the world, and have a very high level of
technical sophistication as well as resources
Hacktivists
individuals or groups placed into this category are typically socially or politically motivated and use cyber
attacks as a way to express their views and beliefs
Insider Threat
individuals who have intentionally or unintentionally abused their power and knowledge of an
organization they work at
Actor Motivations
- Financial Motives
- Political Motives
- Social Motives
Page 3 of 17
VERIFIED ANSWERS 100% GRADED TO PASS
Malware Sandboxing
the process of running a piece of malware in a contained environment, and closely monitoring exactly
what the software does
allows security teams to collect indicators of compromise
Threat Intelligence Lifecycle
1. Planning & Direction
determines what the scope is for this specific threat intelligence project
goals need to be set, and the stakeholders need to be clearly defined
2. Collection
team will go out and collect all of the data they need to achieve their end goal of creating actionable
intelligence
3. Processing
transform data collected into a clear and readable format so that it can be analyzed, typically by human
threat intelligence analysts
4. Analysis
a human process where processed information is turned into actionable intelligence that can be used
- whether to investigate a potential threat
- what actions to take immediately to block an attack
- how to strengthen security controls
- how much to invest in additional security resources
5. Dissemination
getting the finished intelligence output to the places it needs to go
can be SOC, fellow Threat Intelligence Analysts, and even the executive board
6. Feedback
Page 1 of 17
,understand your overall intelligence priorities and the requirements of the security teams that will be
consuming the threat intelligence
SIGNT (Signal intelligence)
involves the interception of radio signals and broadcast communications to gather intelligence
OSINT (Open Source Intelligence)
information that is gathered from public source
HUMINT (Human Intelligence)
information gathered from human sources, often gathered through
- in-person meetings
- debriefings personnel tasked with acquiring information through observation, document gathering, etc
GEOSINT (Geospatial Intelligence)
use of satellite imaging to monitor activities such as
- tracking individuals of interest
- structural reconnaissance
- military movement location and tracking
- monitoring natural disaster
Strategic Threat Intelligence
provides high-level, typically non-technical information that can be understood by anyone
used when presenting to executives and other decision-makers within an organization to aid with
decisions such as budget spending and policy review or creation
Operational Threat Intelligence
studying threat actors that might target the organization, in order to gain information about
- who they are
- their motivations
- their tactics, techniques, and procedures (TTPs)
Page 2 of 17
, Tactical Threat Intelligence
technical in nature and is of immediate value to an organization
shared in the form of indicators of compromise (IOCs) such as
- URLs
- domains
- email addresses
- file hashes
- IP addresses
Cyber Criminals
group includes hackers and crackers that are looking to make money from malicious and illegal activity,
such as
- cyber-attacks
- ransomware
- phishing
Nation-States/APTs
hackers or hacking teams that work for governments around the world, and have a very high level of
technical sophistication as well as resources
Hacktivists
individuals or groups placed into this category are typically socially or politically motivated and use cyber
attacks as a way to express their views and beliefs
Insider Threat
individuals who have intentionally or unintentionally abused their power and knowledge of an
organization they work at
Actor Motivations
- Financial Motives
- Political Motives
- Social Motives
Page 3 of 17