CompTIA CySA+ CS0-003 Threat Intelligence And Threat Hunting Concepts Practice Test
Objective 1.4 • 39 original questions
This CompTIA CySA+ CS0-003 practice test focuses on objective 1.4: threat intelligence and threat hunting concepts. All questions are original ExamSnap scenarios aligned to the official CS0-003 objective set; they are not copied from live CompTIA exam content. Review every option explanation to understand why a choice fits or does not fit the scenario. For broader exam preparation, review the CompTIA CySA+ CS0-003 Exam Dumps page.
Instructions: Select the best answer unless the question explicitly says Select TWO or Select THREE. Review the explanation and option review after answering.
A review at Wide World Importers finds a gap: the team cannot reliably characterize a highly resourced adversary maintaining long-term access. Which option best closes that gap? The organization wants a vendor-neutral approach that can be explained during audit review.
Correct answer: B
Why: An APT is a capable, persistent adversary that pursues strategic objectives over an extended period. It directly fits this scenario because the requirement is to characterize a highly resourced adversary maintaining long-term access.
Option review:
A: Threat intelligence should inform incident response, vulnerability management, risk management, security engineering, and detection teams. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a highly resourced adversary maintaining long-term access.
B: An APT is a capable, persistent adversary that pursues strategic objectives over an extended period. It directly fits this scenario because the requirement is to characterize a highly resourced adversary maintaining long-term access.
C: Indicators of compromise must be collected, validated, analyzed in context, and applied to searches or detections. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a highly resourced adversary maintaining long-term access.
D: Insider threats arise from people with legitimate access and may be intentional or unintentional. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a highly resourced adversary maintaining long-term access.
E: Open sources include public social media, blogs, forums, government bulletins, CERT/CSIRT notices, and portions of the deep or dark web. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a highly resourced adversary maintaining long-term access.
Learning point: Use Advanced persistent threat (APT) when the key requirement is to characterize a highly resourced adversary maintaining long-term access.
a security architect at Datum Fabrication is comparing several approaches. The deciding requirement is to characterize an attacker motivated by public advocacy or ideology. Which option should be chosen? Base the decision on the primary security requirement, not on implementation convenience.
Correct answer: B
Why: Hacktivists are primarily motivated by ideological, political, or social causes. It directly fits this scenario because the requirement is to characterize an attacker motivated by public advocacy or ideology.
Option review:
A: Open sources include public social media, blogs, forums, government bulletins, CERT/CSIRT notices, and portions of the deep or dark web. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize an attacker motivated by public advocacy or ideology.
B: Hacktivists are primarily motivated by ideological, political, or social causes. It directly fits this scenario because the requirement is to characterize an attacker motivated by public advocacy or ideology.
C: Useful intelligence is evaluated for timeliness, relevance, and accuracy before analysts act on it. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize an attacker motivated by public advocacy or ideology.
D: Indicators of compromise must be collected, validated, analyzed in context, and applied to searches or detections. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize an attacker motivated by public advocacy or ideology.
E: A script kiddie relies heavily on existing tools or exploits with limited technical depth. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize an attacker motivated by public advocacy or ideology.
Learning point: Use Hacktivist when the key requirement is to characterize an attacker motivated by public advocacy or ideology.
While supporting an e-commerce platform, a SOC lead is asked to characterize a coordinated threat group driven primarily by profit. Which concept or tool is the clearest match? The environment follows least privilege and preserves evidence where incident handling is involved.
Correct answer: E
Why: Organized criminal groups commonly pursue financial gain through fraud, extortion, theft, or illicit services. It directly fits this scenario because the requirement is to characterize a coordinated threat group driven primarily by profit.
Option review:
A: Nation-state actors pursue geopolitical, intelligence, military, or strategic national objectives and may have substantial resources. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a coordinated threat group driven primarily by profit.
B: Open sources include public social media, blogs, forums, government bulletins, CERT/CSIRT notices, and portions of the deep or dark web. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a coordinated threat group driven primarily by profit.
C: Useful intelligence is evaluated for timeliness, relevance, and accuracy before analysts act on it. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a coordinated threat group driven primarily by profit.
D: Hunting can prioritize misconfigurations, isolated networks, business-critical assets, and high-value processes based on risk. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a coordinated threat group driven primarily by profit.
E: Organized criminal groups commonly pursue financial gain through fraud, extortion, theft, or illicit services. It directly fits this scenario because the requirement is to characterize a coordinated threat group driven primarily by profit.
Learning point: Use Organized cybercrime when the key requirement is to characterize a coordinated threat group driven primarily by profit.
At Proseware Research, a malware analyst has two simultaneous requirements: characterize an adversary conducting operations for national strategic interests, and use subscription, sharing-community, or internal-only intelligence. Which TWO options should be selected? Use the choice that most directly addresses the stated evidence rather than a broader control.
Correct answers: C, E
Why: Closed sources include paid feeds, information-sharing groups, and internal organizational data. It directly fits this scenario because the requirement is to use subscription, sharing-community, or internal-only intelligence. Nation-state actors pursue geopolitical, intelligence, military, or strategic national objectives and may have substantial resources. It directly fits this scenario because the requirement is to characterize an adversary conducting operations for national strategic interests.
Option review:
A: Threat intelligence should inform incident response, vulnerability management, risk management, security engineering, and detection teams. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize an adversary conducting operations for national strategic interests; use subscription, sharing-community, or internal-only intelligence.
B: Useful intelligence is evaluated for timeliness, relevance, and accuracy before analysts act on it. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize an adversary conducting operations for national strategic interests; use subscription, sharing-community, or internal-only intelligence.
C: Closed sources include paid feeds, information-sharing groups, and internal organizational data. It directly fits this scenario because the requirement is to use subscription, sharing-community, or internal-only intelligence.
D: Insider threats arise from people with legitimate access and may be intentional or unintentional. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize an adversary conducting operations for national strategic interests; use subscription, sharing-community, or internal-only intelligence.
E: Nation-state actors pursue geopolitical, intelligence, military, or strategic national objectives and may have substantial resources. It directly fits this scenario because the requirement is to characterize an adversary conducting operations for national strategic interests.
Learning point: Use Nation-state actor, Closed-source intelligence when the key requirement is to characterize an adversary conducting operations for national strategic interests; use subscription, sharing-community, or internal-only intelligence.
The primary objective for Wingtip Services is to characterize a low-skill attacker using readily available tools without deep understanding. Which selection best satisfies that objective in a managed cloud environment? The team wants the most defensible analyst action before expanding the investigation.
Correct answer: B
Why: A script kiddie relies heavily on existing tools or exploits with limited technical depth. It directly fits this scenario because the requirement is to characterize a low-skill attacker using readily available tools without deep understanding.
Option review:
A: Useful intelligence is evaluated for timeliness, relevance, and accuracy before analysts act on it. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a low-skill attacker using readily available tools without deep understanding.
B: A script kiddie relies heavily on existing tools or exploits with limited technical depth. It directly fits this scenario because the requirement is to characterize a low-skill attacker using readily available tools without deep understanding.
C: Open sources include public social media, blogs, forums, government bulletins, CERT/CSIRT notices, and portions of the deep or dark web. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a low-skill attacker using readily available tools without deep understanding.
D: Hunting can prioritize misconfigurations, isolated networks, business-critical assets, and high-value processes based on risk. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a low-skill attacker using readily available tools without deep understanding.
E: Closed sources include paid feeds, information-sharing groups, and internal organizational data. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a low-skill attacker using readily available tools without deep understanding.
Learning point: Use Script kiddie when the key requirement is to characterize a low-skill attacker using readily available tools without deep understanding.
At Woodgrove Bank, a threat hunter needs to assess risk from a trusted user who misuses access deliberately or accidentally. Which option is the BEST fit for a high-value payment environment? Select based on the scenario’s decisive constraint, not on which technology is newest.
Correct answer: A
Why: Insider threats arise from people with legitimate access and may be intentional or unintentional. It directly fits this scenario because the requirement is to assess risk from a trusted user who misuses access deliberately or accidentally.
Option review:
A: Insider threats arise from people with legitimate access and may be intentional or unintentional. It directly fits this scenario because the requirement is to assess risk from a trusted user who misuses access deliberately or accidentally.
B: TTPs describe how adversaries pursue objectives and can help analysts connect behavior across incidents. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to assess risk from a trusted user who misuses access deliberately or accidentally.
C: Active defense uses controlled defensive measures; honeypots deliberately attract or observe adversary activity in instrumented decoy systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to assess risk from a trusted user who misuses access deliberately or accidentally.
D: Organized criminal groups commonly pursue financial gain through fraud, extortion, theft, or illicit services. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to assess risk from a trusted user who misuses access deliberately or accidentally.
E: Hunting can prioritize misconfigurations, isolated networks, business-critical assets, and high-value processes based on risk. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to assess risk from a trusted user who misuses access deliberately or accidentally.
Learning point: Use Insider threat when the key requirement is to assess risk from a trusted user who misuses access deliberately or accidentally.
For a regulated customer-data environment, a risk analyst must satisfy all three needs: investigate compromise introduced through a trusted vendor or software dependency; route relevant intelligence to teams that can change controls, priorities, and detections; and characterize an attacker motivated by public advocacy or ideology. Select THREE. Assume the activity is authorized and must follow normal enterprise change control.
Correct answers: A, C, D
Why: Hacktivists are primarily motivated by ideological, political, or social causes. It directly fits this scenario because the requirement is to characterize an attacker motivated by public advocacy or ideology. Supply-chain compromise targets trusted vendors, software, updates, dependencies, or service providers to reach downstream victims. It directly fits this scenario because the requirement is to investigate compromise introduced through a trusted vendor or software dependency. Threat intelligence should inform incident response, vulnerability management, risk management, security engineering, and detection teams. It directly fits this scenario because the requirement is to route relevant intelligence to teams that can change controls, priorities, and detections.
Option review:
A: Hacktivists are primarily motivated by ideological, political, or social causes. It directly fits this scenario because the requirement is to characterize an attacker motivated by public advocacy or ideology.
B: Closed sources include paid feeds, information-sharing groups, and internal organizational data. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to investigate compromise introduced through a trusted vendor or software dependency; route relevant intelligence to teams that can change controls, priorities, and detections; characterize an attacker motivated by public advocacy or ideology.
C: Supply-chain compromise targets trusted vendors, software, updates, dependencies, or service providers to reach downstream victims. It directly fits this scenario because the requirement is to investigate compromise introduced through a trusted vendor or software dependency.
D: Threat intelligence should inform incident response, vulnerability management, risk management, security engineering, and detection teams. It directly fits this scenario because the requirement is to route relevant intelligence to teams that can change controls, priorities, and detections.
E: Hunting can prioritize misconfigurations, isolated networks, business-critical assets, and high-value processes based on risk. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to investigate compromise introduced through a trusted vendor or software dependency; route relevant intelligence to teams that can change controls, priorities, and detections; characterize an attacker motivated by public advocacy or ideology.
Learning point: Use Supply-chain threat, Cross-functional intelligence sharing, Hacktivist when the key requirement is to investigate compromise introduced through a trusted vendor or software dependency; route relevant intelligence to teams that can change controls, priorities, and detections; characterize an attacker motivated by public advocacy or ideology.
Contoso Health is updating its security operations standard for a hospital network. Which option most directly helps the team describe recurring adversary behavior patterns rather than a single indicator? Assume no additional product-specific features are available beyond the concepts listed.
Correct answer: B
Why: TTPs describe how adversaries pursue objectives and can help analysts connect behavior across incidents. It directly fits this scenario because the requirement is to describe recurring adversary behavior patterns rather than a single indicator.
Option review:
A: Insider threats arise from people with legitimate access and may be intentional or unintentional. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to describe recurring adversary behavior patterns rather than a single indicator.
B: TTPs describe how adversaries pursue objectives and can help analysts connect behavior across incidents. It directly fits this scenario because the requirement is to describe recurring adversary behavior patterns rather than a single indicator.
C: Supply-chain compromise targets trusted vendors, software, updates, dependencies, or service providers to reach downstream victims. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to describe recurring adversary behavior patterns rather than a single indicator.
D: Organized criminal groups commonly pursue financial gain through fraud, extortion, theft, or illicit services. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to describe recurring adversary behavior patterns rather than a single indicator.
E: Indicators of compromise must be collected, validated, analyzed in context, and applied to searches or detections. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to describe recurring adversary behavior patterns rather than a single indicator.
Learning point: Use Tactics, techniques, and procedures (TTPs) when the key requirement is to describe recurring adversary behavior patterns rather than a single indicator.
A ticket at Blue Yonder Airlines asks a security operations engineer to decide whether a threat report is current, applicable, and trustworthy enough to use. Which choice addresses the requirement most directly? The organization wants a vendor-neutral approach that can be explained during audit review.
Correct answer: D
Why: Useful intelligence is evaluated for timeliness, relevance, and accuracy before analysts act on it. It directly fits this scenario because the requirement is to decide whether a threat report is current, applicable, and trustworthy enough to use.
Option review:
A: TTPs describe how adversaries pursue objectives and can help analysts connect behavior across incidents. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to decide whether a threat report is current, applicable, and trustworthy enough to use.
B: Open sources include public social media, blogs, forums, government bulletins, CERT/CSIRT notices, and portions of the deep or dark web. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to decide whether a threat report is current, applicable, and trustworthy enough to use.
C: Hunting can prioritize misconfigurations, isolated networks, business-critical assets, and high-value processes based on risk. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to decide whether a threat report is current, applicable, and trustworthy enough to use.
D: Useful intelligence is evaluated for timeliness, relevance, and accuracy before analysts act on it. It directly fits this scenario because the requirement is to decide whether a threat report is current, applicable, and trustworthy enough to use.
E: Threat intelligence should inform incident response, vulnerability management, risk management, security engineering, and detection teams. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to decide whether a threat report is current, applicable, and trustworthy enough to use.
Learning point: Use Threat-intelligence confidence when the key requirement is to decide whether a threat report is current, applicable, and trustworthy enough to use.
In a remote-work environment, a detection engineer must collect threat information from publicly accessible sources. Which approach is MOST appropriate? Base the decision on the primary security requirement, not on implementation convenience.
Correct answer: D
Why: Open sources include public social media, blogs, forums, government bulletins, CERT/CSIRT notices, and portions of the deep or dark web. It directly fits this scenario because the requirement is to collect threat information from publicly accessible sources.
Option review:
A: A script kiddie relies heavily on existing tools or exploits with limited technical depth. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect threat information from publicly accessible sources.
B: Hunting can prioritize misconfigurations, isolated networks, business-critical assets, and high-value processes based on risk. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect threat information from publicly accessible sources.
C: Hacktivists are primarily motivated by ideological, political, or social causes. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect threat information from publicly accessible sources.
D: Open sources include public social media, blogs, forums, government bulletins, CERT/CSIRT notices, and portions of the deep or dark web. It directly fits this scenario because the requirement is to collect threat information from publicly accessible sources.
E: TTPs describe how adversaries pursue objectives and can help analysts connect behavior across incidents. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect threat information from publicly accessible sources.
Learning point: Use Open-source intelligence when the key requirement is to collect threat information from publicly accessible sources.
During a security review, a vulnerability analyst must address two separate needs: use subscription, sharing-community, or internal-only intelligence, and characterize a coordinated threat group driven primarily by profit. Select TWO. The environment follows least privilege and preserves evidence where incident handling is involved.
Correct answers: A, E
Why: Organized criminal groups commonly pursue financial gain through fraud, extortion, theft, or illicit services. It directly fits this scenario because the requirement is to characterize a coordinated threat group driven primarily by profit. Closed sources include paid feeds, information-sharing groups, and internal organizational data. It directly fits this scenario because the requirement is to use subscription, sharing-community, or internal-only intelligence.
Option review:
A: Organized criminal groups commonly pursue financial gain through fraud, extortion, theft, or illicit services. It directly fits this scenario because the requirement is to characterize a coordinated threat group driven primarily by profit.
B: An APT is a capable, persistent adversary that pursues strategic objectives over an extended period. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use subscription, sharing-community, or internal-only intelligence; characterize a coordinated threat group driven primarily by profit.
C: Useful intelligence is evaluated for timeliness, relevance, and accuracy before analysts act on it. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use subscription, sharing-community, or internal-only intelligence; characterize a coordinated threat group driven primarily by profit.
D: Nation-state actors pursue geopolitical, intelligence, military, or strategic national objectives and may have substantial resources. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use subscription, sharing-community, or internal-only intelligence; characterize a coordinated threat group driven primarily by profit.
E: Closed sources include paid feeds, information-sharing groups, and internal organizational data. It directly fits this scenario because the requirement is to use subscription, sharing-community, or internal-only intelligence.
Learning point: Use Closed-source intelligence, Organized cybercrime when the key requirement is to use subscription, sharing-community, or internal-only intelligence; characterize a coordinated threat group driven primarily by profit.
an OT security analyst at City Power Utilities is comparing several approaches. The deciding requirement is to route relevant intelligence to teams that can change controls, priorities, and detections. Which option should be chosen? Use the choice that most directly addresses the stated evidence rather than a broader control.
Correct answer: E
Why: Threat intelligence should inform incident response, vulnerability management, risk management, security engineering, and detection teams. It directly fits this scenario because the requirement is to route relevant intelligence to teams that can change controls, priorities, and detections.
Option review:
A: Nation-state actors pursue geopolitical, intelligence, military, or strategic national objectives and may have substantial resources. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to route relevant intelligence to teams that can change controls, priorities, and detections.
B: Supply-chain compromise targets trusted vendors, software, updates, dependencies, or service providers to reach downstream victims. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to route relevant intelligence to teams that can change controls, priorities, and detections.
C: A script kiddie relies heavily on existing tools or exploits with limited technical depth. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to route relevant intelligence to teams that can change controls, priorities, and detections.
D: An APT is a capable, persistent adversary that pursues strategic objectives over an extended period. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to route relevant intelligence to teams that can change controls, priorities, and detections.
E: Threat intelligence should inform incident response, vulnerability management, risk management, security engineering, and detection teams. It directly fits this scenario because the requirement is to route relevant intelligence to teams that can change controls, priorities, and detections.
Learning point: Use Cross-functional intelligence sharing when the key requirement is to route relevant intelligence to teams that can change controls, priorities, and detections.
While supporting a newly acquired subsidiary, a security consultant is asked to turn observed indicators into hunting queries or detection content. Which concept or tool is the clearest match? The team wants the most defensible analyst action before expanding the investigation.
Correct answer: B
Why: Indicators of compromise must be collected, validated, analyzed in context, and applied to searches or detections. It directly fits this scenario because the requirement is to turn observed indicators into hunting queries or detection content.
Option review:
A: Hacktivists are primarily motivated by ideological, political, or social causes. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn observed indicators into hunting queries or detection content.
B: Indicators of compromise must be collected, validated, analyzed in context, and applied to searches or detections. It directly fits this scenario because the requirement is to turn observed indicators into hunting queries or detection content.
C: Useful intelligence is evaluated for timeliness, relevance, and accuracy before analysts act on it. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn observed indicators into hunting queries or detection content.
D: Active defense uses controlled defensive measures; honeypots deliberately attract or observe adversary activity in instrumented decoy systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn observed indicators into hunting queries or detection content.
E: Threat intelligence should inform incident response, vulnerability management, risk management, security engineering, and detection teams. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn observed indicators into hunting queries or detection content.
Learning point: Use IoC collection and analysis when the key requirement is to turn observed indicators into hunting queries or detection content.
A new security procedure at Northwind Traders must enable analysts to choose a hunting scope based on risky configuration or business-critical assets. Which option is the BEST choice? Select based on the scenario’s decisive constraint, not on which technology is newest.
Correct answer: E
Why: Hunting can prioritize misconfigurations, isolated networks, business-critical assets, and high-value processes based on risk. It directly fits this scenario because the requirement is to choose a hunting scope based on risky configuration or business-critical assets.
Option review:
A: Closed sources include paid feeds, information-sharing groups, and internal organizational data. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to choose a hunting scope based on risky configuration or business-critical assets.
B: Insider threats arise from people with legitimate access and may be intentional or unintentional. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to choose a hunting scope based on risky configuration or business-critical assets.
C: Useful intelligence is evaluated for timeliness, relevance, and accuracy before analysts act on it. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to choose a hunting scope based on risky configuration or business-critical assets.
D: TTPs describe how adversaries pursue objectives and can help analysts connect behavior across incidents. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to choose a hunting scope based on risky configuration or business-critical assets.
E: Hunting can prioritize misconfigurations, isolated networks, business-critical assets, and high-value processes based on risk. It directly fits this scenario because the requirement is to choose a hunting scope based on risky configuration or business-critical assets.
Learning point: Use Threat-hunting focus areas when the key requirement is to choose a hunting scope based on risky configuration or business-critical assets.
During a security review, a cloud security analyst must address two separate needs: deploy a monitored decoy to collect attacker behavior with minimal production risk, and investigate compromise introduced through a trusted vendor or software dependency. Select TWO. Assume the activity is authorized and must follow normal enterprise change control.
Correct answers: D, E
Why: Active defense uses controlled defensive measures; honeypots deliberately attract or observe adversary activity in instrumented decoy systems. It directly fits this scenario because the requirement is to deploy a monitored decoy to collect attacker behavior with minimal production risk. Supply-chain compromise targets trusted vendors, software, updates, dependencies, or service providers to reach downstream victims. It directly fits this scenario because the requirement is to investigate compromise introduced through a trusted vendor or software dependency.
Option review:
A: An APT is a capable, persistent adversary that pursues strategic objectives over an extended period. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to deploy a monitored decoy to collect attacker behavior with minimal production risk; investigate compromise introduced through a trusted vendor or software dependency.
B: Useful intelligence is evaluated for timeliness, relevance, and accuracy before analysts act on it. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to deploy a monitored decoy to collect attacker behavior with minimal production risk; investigate compromise introduced through a trusted vendor or software dependency.
C: Nation-state actors pursue geopolitical, intelligence, military, or strategic national objectives and may have substantial resources. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to deploy a monitored decoy to collect attacker behavior with minimal production risk; investigate compromise introduced through a trusted vendor or software dependency.
D: Active defense uses controlled defensive measures; honeypots deliberately attract or observe adversary activity in instrumented decoy systems. It directly fits this scenario because the requirement is to deploy a monitored decoy to collect attacker behavior with minimal production risk.
E: Supply-chain compromise targets trusted vendors, software, updates, dependencies, or service providers to reach downstream victims. It directly fits this scenario because the requirement is to investigate compromise introduced through a trusted vendor or software dependency.
Learning point: Use Active defense and honeypots, Supply-chain threat when the key requirement is to deploy a monitored decoy to collect attacker behavior with minimal production risk; investigate compromise introduced through a trusted vendor or software dependency.
At Coho Winery, a systems security analyst needs to characterize a highly resourced adversary maintaining long-term access. Which option is the BEST fit for a branch-office network? Assume no additional product-specific features are available beyond the concepts listed.
Correct answer: C
Why: An APT is a capable, persistent adversary that pursues strategic objectives over an extended period. It directly fits this scenario because the requirement is to characterize a highly resourced adversary maintaining long-term access.
Option review:
A: Insider threats arise from people with legitimate access and may be intentional or unintentional. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a highly resourced adversary maintaining long-term access.
B: Nation-state actors pursue geopolitical, intelligence, military, or strategic national objectives and may have substantial resources. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a highly resourced adversary maintaining long-term access.
C: An APT is a capable, persistent adversary that pursues strategic objectives over an extended period. It directly fits this scenario because the requirement is to characterize a highly resourced adversary maintaining long-term access.
D: TTPs describe how adversaries pursue objectives and can help analysts connect behavior across incidents. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a highly resourced adversary maintaining long-term access.
E: Hunting can prioritize misconfigurations, isolated networks, business-critical assets, and high-value processes based on risk. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a highly resourced adversary maintaining long-term access.
Learning point: Use Advanced persistent threat (APT) when the key requirement is to characterize a highly resourced adversary maintaining long-term access.
During an investigation at Litware Manufacturing, the immediate requirement is to characterize an attacker motivated by public advocacy or ideology. What should an incident responder select? The organization wants a vendor-neutral approach that can be explained during audit review.
Correct answer: E
Why: Hacktivists are primarily motivated by ideological, political, or social causes. It directly fits this scenario because the requirement is to characterize an attacker motivated by public advocacy or ideology.
Option review:
A: A script kiddie relies heavily on existing tools or exploits with limited technical depth. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize an attacker motivated by public advocacy or ideology.
B: Nation-state actors pursue geopolitical, intelligence, military, or strategic national objectives and may have substantial resources. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize an attacker motivated by public advocacy or ideology.
C: Hunting can prioritize misconfigurations, isolated networks, business-critical assets, and high-value processes based on risk. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize an attacker motivated by public advocacy or ideology.
D: Useful intelligence is evaluated for timeliness, relevance, and accuracy before analysts act on it. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize an attacker motivated by public advocacy or ideology.
E: Hacktivists are primarily motivated by ideological, political, or social causes. It directly fits this scenario because the requirement is to characterize an attacker motivated by public advocacy or ideology.
Learning point: Use Hacktivist when the key requirement is to characterize an attacker motivated by public advocacy or ideology.
Fourth Coffee is updating its security operations standard for a multi-site enterprise. Which option most directly helps the team characterize a coordinated threat group driven primarily by profit? Base the decision on the primary security requirement, not on implementation convenience.
Correct answer: E
Why: Organized criminal groups commonly pursue financial gain through fraud, extortion, theft, or illicit services. It directly fits this scenario because the requirement is to characterize a coordinated threat group driven primarily by profit.
Option review:
A: Closed sources include paid feeds, information-sharing groups, and internal organizational data. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a coordinated threat group driven primarily by profit.
B: Hacktivists are primarily motivated by ideological, political, or social causes. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a coordinated threat group driven primarily by profit.
C: Active defense uses controlled defensive measures; honeypots deliberately attract or observe adversary activity in instrumented decoy systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a coordinated threat group driven primarily by profit.
D: An APT is a capable, persistent adversary that pursues strategic objectives over an extended period. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a coordinated threat group driven primarily by profit.
E: Organized criminal groups commonly pursue financial gain through fraud, extortion, theft, or illicit services. It directly fits this scenario because the requirement is to characterize a coordinated threat group driven primarily by profit.
Learning point: Use Organized cybercrime when the key requirement is to characterize a coordinated threat group driven primarily by profit.
During a security review, a response lead must address two separate needs: characterize an adversary conducting operations for national strategic interests, and use subscription, sharing-community, or internal-only intelligence. Select TWO. The environment follows least privilege and preserves evidence where incident handling is involved.
Correct answers: A, E
Why: Nation-state actors pursue geopolitical, intelligence, military, or strategic national objectives and may have substantial resources. It directly fits this scenario because the requirement is to characterize an adversary conducting operations for national strategic interests. Closed sources include paid feeds, information-sharing groups, and internal organizational data. It directly fits this scenario because the requirement is to use subscription, sharing-community, or internal-only intelligence.
Option review:
A: Nation-state actors pursue geopolitical, intelligence, military, or strategic national objectives and may have substantial resources. It directly fits this scenario because the requirement is to characterize an adversary conducting operations for national strategic interests.
B: TTPs describe how adversaries pursue objectives and can help analysts connect behavior across incidents. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize an adversary conducting operations for national strategic interests; use subscription, sharing-community, or internal-only intelligence.
C: Organized criminal groups commonly pursue financial gain through fraud, extortion, theft, or illicit services. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize an adversary conducting operations for national strategic interests; use subscription, sharing-community, or internal-only intelligence.
D: Supply-chain compromise targets trusted vendors, software, updates, dependencies, or service providers to reach downstream victims. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize an adversary conducting operations for national strategic interests; use subscription, sharing-community, or internal-only intelligence.
E: Closed sources include paid feeds, information-sharing groups, and internal organizational data. It directly fits this scenario because the requirement is to use subscription, sharing-community, or internal-only intelligence.
Learning point: Use Nation-state actor, Closed-source intelligence when the key requirement is to characterize an adversary conducting operations for national strategic interests; use subscription, sharing-community, or internal-only intelligence.
In a hybrid-cloud workload, a blue-team analyst must characterize a low-skill attacker using readily available tools without deep understanding. Which approach is MOST appropriate? Use the choice that most directly addresses the stated evidence rather than a broader control.
Correct answer: C
Why: A script kiddie relies heavily on existing tools or exploits with limited technical depth. It directly fits this scenario because the requirement is to characterize a low-skill attacker using readily available tools without deep understanding.
Option review:
A: Useful intelligence is evaluated for timeliness, relevance, and accuracy before analysts act on it. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a low-skill attacker using readily available tools without deep understanding.
B: Hunting can prioritize misconfigurations, isolated networks, business-critical assets, and high-value processes based on risk. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a low-skill attacker using readily available tools without deep understanding.
C: A script kiddie relies heavily on existing tools or exploits with limited technical depth. It directly fits this scenario because the requirement is to characterize a low-skill attacker using readily available tools without deep understanding.
D: Closed sources include paid feeds, information-sharing groups, and internal organizational data. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a low-skill attacker using readily available tools without deep understanding.
E: Insider threats arise from people with legitimate access and may be intentional or unintentional. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a low-skill attacker using readily available tools without deep understanding.
Learning point: Use Script kiddie when the key requirement is to characterize a low-skill attacker using readily available tools without deep understanding.
For a global corporate network, an incident coordinator must satisfy all three needs: assess risk from a trusted user who misuses access deliberately or accidentally; use subscription, sharing-community, or internal-only intelligence; and characterize a highly resourced adversary maintaining long-term access. Select THREE. The team wants the most defensible analyst action before expanding the investigation.
Correct answers: A, C, D
Why: Insider threats arise from people with legitimate access and may be intentional or unintentional. It directly fits this scenario because the requirement is to assess risk from a trusted user who misuses access deliberately or accidentally. Closed sources include paid feeds, information-sharing groups, and internal organizational data. It directly fits this scenario because the requirement is to use subscription, sharing-community, or internal-only intelligence. An APT is a capable, persistent adversary that pursues strategic objectives over an extended period. It directly fits this scenario because the requirement is to characterize a highly resourced adversary maintaining long-term access.
Option review:
A: Insider threats arise from people with legitimate access and may be intentional or unintentional. It directly fits this scenario because the requirement is to assess risk from a trusted user who misuses access deliberately or accidentally.
B: A script kiddie relies heavily on existing tools or exploits with limited technical depth. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to assess risk from a trusted user who misuses access deliberately or accidentally; use subscription, sharing-community, or internal-only intelligence; characterize a highly resourced adversary maintaining long-term access.
C: Closed sources include paid feeds, information-sharing groups, and internal organizational data. It directly fits this scenario because the requirement is to use subscription, sharing-community, or internal-only intelligence.
D: An APT is a capable, persistent adversary that pursues strategic objectives over an extended period. It directly fits this scenario because the requirement is to characterize a highly resourced adversary maintaining long-term access.
E: Organized criminal groups commonly pursue financial gain through fraud, extortion, theft, or illicit services. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to assess risk from a trusted user who misuses access deliberately or accidentally; use subscription, sharing-community, or internal-only intelligence; characterize a highly resourced adversary maintaining long-term access.
Learning point: Use Insider threat, Closed-source intelligence, Advanced persistent threat (APT) when the key requirement is to assess risk from a trusted user who misuses access deliberately or accidentally; use subscription, sharing-community, or internal-only intelligence; characterize a highly resourced adversary maintaining long-term access.
a security architect at Datum Fabrication is comparing several approaches. The deciding requirement is to investigate compromise introduced through a trusted vendor or software dependency. Which option should be chosen? Select based on the scenario’s decisive constraint, not on which technology is newest.
Correct answer: B
Why: Supply-chain compromise targets trusted vendors, software, updates, dependencies, or service providers to reach downstream victims. It directly fits this scenario because the requirement is to investigate compromise introduced through a trusted vendor or software dependency.
Option review:
A: Nation-state actors pursue geopolitical, intelligence, military, or strategic national objectives and may have substantial resources. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to investigate compromise introduced through a trusted vendor or software dependency.
B: Supply-chain compromise targets trusted vendors, software, updates, dependencies, or service providers to reach downstream victims. It directly fits this scenario because the requirement is to investigate compromise introduced through a trusted vendor or software dependency.
C: Indicators of compromise must be collected, validated, analyzed in context, and applied to searches or detections. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to investigate compromise introduced through a trusted vendor or software dependency.
D: Active defense uses controlled defensive measures; honeypots deliberately attract or observe adversary activity in instrumented decoy systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to investigate compromise introduced through a trusted vendor or software dependency.
E: Open sources include public social media, blogs, forums, government bulletins, CERT/CSIRT notices, and portions of the deep or dark web. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to investigate compromise introduced through a trusted vendor or software dependency.
Learning point: Use Supply-chain threat when the key requirement is to investigate compromise introduced through a trusted vendor or software dependency.
While supporting an e-commerce platform, a SOC lead is asked to describe recurring adversary behavior patterns rather than a single indicator. Which concept or tool is the clearest match? Assume the activity is authorized and must follow normal enterprise change control.
Correct answer: D
Why: TTPs describe how adversaries pursue objectives and can help analysts connect behavior across incidents. It directly fits this scenario because the requirement is to describe recurring adversary behavior patterns rather than a single indicator.
Option review:
A: Hunting can prioritize misconfigurations, isolated networks, business-critical assets, and high-value processes based on risk. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to describe recurring adversary behavior patterns rather than a single indicator.
B: Insider threats arise from people with legitimate access and may be intentional or unintentional. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to describe recurring adversary behavior patterns rather than a single indicator.
C: Useful intelligence is evaluated for timeliness, relevance, and accuracy before analysts act on it. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to describe recurring adversary behavior patterns rather than a single indicator.
D: TTPs describe how adversaries pursue objectives and can help analysts connect behavior across incidents. It directly fits this scenario because the requirement is to describe recurring adversary behavior patterns rather than a single indicator.
E: An APT is a capable, persistent adversary that pursues strategic objectives over an extended period. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to describe recurring adversary behavior patterns rather than a single indicator.
Learning point: Use Tactics, techniques, and procedures (TTPs) when the key requirement is to describe recurring adversary behavior patterns rather than a single indicator.
A new security procedure at Proseware Research must enable analysts to decide whether a threat report is current, applicable, and trustworthy enough to use. Which option is the BEST choice? Assume no additional product-specific features are available beyond the concepts listed.
Correct answer: E
Why: Useful intelligence is evaluated for timeliness, relevance, and accuracy before analysts act on it. It directly fits this scenario because the requirement is to decide whether a threat report is current, applicable, and trustworthy enough to use.
Option review:
A: Active defense uses controlled defensive measures; honeypots deliberately attract or observe adversary activity in instrumented decoy systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to decide whether a threat report is current, applicable, and trustworthy enough to use.
B: Organized criminal groups commonly pursue financial gain through fraud, extortion, theft, or illicit services. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to decide whether a threat report is current, applicable, and trustworthy enough to use.
C: Hacktivists are primarily motivated by ideological, political, or social causes. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to decide whether a threat report is current, applicable, and trustworthy enough to use.
D: TTPs describe how adversaries pursue objectives and can help analysts connect behavior across incidents. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to decide whether a threat report is current, applicable, and trustworthy enough to use.
E: Useful intelligence is evaluated for timeliness, relevance, and accuracy before analysts act on it. It directly fits this scenario because the requirement is to decide whether a threat report is current, applicable, and trustworthy enough to use.
Learning point: Use Threat-intelligence confidence when the key requirement is to decide whether a threat report is current, applicable, and trustworthy enough to use.
The primary objective for Wingtip Services is to collect threat information from publicly accessible sources. Which selection best satisfies that objective in a managed cloud environment? The organization wants a vendor-neutral approach that can be explained during audit review.
Correct answer: D
Why: Open sources include public social media, blogs, forums, government bulletins, CERT/CSIRT notices, and portions of the deep or dark web. It directly fits this scenario because the requirement is to collect threat information from publicly accessible sources.
Option review:
A: Indicators of compromise must be collected, validated, analyzed in context, and applied to searches or detections. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect threat information from publicly accessible sources.
B: Hunting can prioritize misconfigurations, isolated networks, business-critical assets, and high-value processes based on risk. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect threat information from publicly accessible sources.
C: A script kiddie relies heavily on existing tools or exploits with limited technical depth. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect threat information from publicly accessible sources.
D: Open sources include public social media, blogs, forums, government bulletins, CERT/CSIRT notices, and portions of the deep or dark web. It directly fits this scenario because the requirement is to collect threat information from publicly accessible sources.
E: Insider threats arise from people with legitimate access and may be intentional or unintentional. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect threat information from publicly accessible sources.
Learning point: Use Open-source intelligence when the key requirement is to collect threat information from publicly accessible sources.
At Woodgrove Bank, a threat hunter needs to use subscription, sharing-community, or internal-only intelligence. Which option is the BEST fit for a high-value payment environment? Base the decision on the primary security requirement, not on implementation convenience.
Correct answer: E
Why: Closed sources include paid feeds, information-sharing groups, and internal organizational data. It directly fits this scenario because the requirement is to use subscription, sharing-community, or internal-only intelligence.
Option review:
A: Useful intelligence is evaluated for timeliness, relevance, and accuracy before analysts act on it. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use subscription, sharing-community, or internal-only intelligence.
B: Organized criminal groups commonly pursue financial gain through fraud, extortion, theft, or illicit services. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use subscription, sharing-community, or internal-only intelligence.
C: Insider threats arise from people with legitimate access and may be intentional or unintentional. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use subscription, sharing-community, or internal-only intelligence.
D: Supply-chain compromise targets trusted vendors, software, updates, dependencies, or service providers to reach downstream victims. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use subscription, sharing-community, or internal-only intelligence.
E: Closed sources include paid feeds, information-sharing groups, and internal organizational data. It directly fits this scenario because the requirement is to use subscription, sharing-community, or internal-only intelligence.
Learning point: Use Closed-source intelligence when the key requirement is to use subscription, sharing-community, or internal-only intelligence.
During an investigation at Humongous Insurance, the immediate requirement is to route relevant intelligence to teams that can change controls, priorities, and detections. What should a risk analyst select? The environment follows least privilege and preserves evidence where incident handling is involved.
Correct answer: B
Why: Threat intelligence should inform incident response, vulnerability management, risk management, security engineering, and detection teams. It directly fits this scenario because the requirement is to route relevant intelligence to teams that can change controls, priorities, and detections.
Option review:
A: TTPs describe how adversaries pursue objectives and can help analysts connect behavior across incidents. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to route relevant intelligence to teams that can change controls, priorities, and detections.
B: Threat intelligence should inform incident response, vulnerability management, risk management, security engineering, and detection teams. It directly fits this scenario because the requirement is to route relevant intelligence to teams that can change controls, priorities, and detections.
C: Closed sources include paid feeds, information-sharing groups, and internal organizational data. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to route relevant intelligence to teams that can change controls, priorities, and detections.
D: Organized criminal groups commonly pursue financial gain through fraud, extortion, theft, or illicit services. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to route relevant intelligence to teams that can change controls, priorities, and detections.
E: Open sources include public social media, blogs, forums, government bulletins, CERT/CSIRT notices, and portions of the deep or dark web. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to route relevant intelligence to teams that can change controls, priorities, and detections.
Learning point: Use Cross-functional intelligence sharing when the key requirement is to route relevant intelligence to teams that can change controls, priorities, and detections.
At Contoso Health, a SOC analyst has two simultaneous requirements: turn observed indicators into hunting queries or detection content, and characterize a low-skill attacker using readily available tools without deep understanding. Which TWO options should be selected? Use the choice that most directly addresses the stated evidence rather than a broader control.
Correct answers: A, D
Why: Indicators of compromise must be collected, validated, analyzed in context, and applied to searches or detections. It directly fits this scenario because the requirement is to turn observed indicators into hunting queries or detection content. A script kiddie relies heavily on existing tools or exploits with limited technical depth. It directly fits this scenario because the requirement is to characterize a low-skill attacker using readily available tools without deep understanding.
Option review:
A: Indicators of compromise must be collected, validated, analyzed in context, and applied to searches or detections. It directly fits this scenario because the requirement is to turn observed indicators into hunting queries or detection content.
B: Hacktivists are primarily motivated by ideological, political, or social causes. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn observed indicators into hunting queries or detection content; characterize a low-skill attacker using readily available tools without deep understanding.
C: Closed sources include paid feeds, information-sharing groups, and internal organizational data. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn observed indicators into hunting queries or detection content; characterize a low-skill attacker using readily available tools without deep understanding.
D: A script kiddie relies heavily on existing tools or exploits with limited technical depth. It directly fits this scenario because the requirement is to characterize a low-skill attacker using readily available tools without deep understanding.
E: Nation-state actors pursue geopolitical, intelligence, military, or strategic national objectives and may have substantial resources. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to turn observed indicators into hunting queries or detection content; characterize a low-skill attacker using readily available tools without deep understanding.
Learning point: Use IoC collection and analysis, Script kiddie when the key requirement is to turn observed indicators into hunting queries or detection content; characterize a low-skill attacker using readily available tools without deep understanding.
A ticket at Blue Yonder Airlines asks a security operations engineer to choose a hunting scope based on risky configuration or business-critical assets. Which choice addresses the requirement most directly? The team wants the most defensible analyst action before expanding the investigation.
Correct answer: B
Why: Hunting can prioritize misconfigurations, isolated networks, business-critical assets, and high-value processes based on risk. It directly fits this scenario because the requirement is to choose a hunting scope based on risky configuration or business-critical assets.
Option review:
A: Supply-chain compromise targets trusted vendors, software, updates, dependencies, or service providers to reach downstream victims. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to choose a hunting scope based on risky configuration or business-critical assets.
B: Hunting can prioritize misconfigurations, isolated networks, business-critical assets, and high-value processes based on risk. It directly fits this scenario because the requirement is to choose a hunting scope based on risky configuration or business-critical assets.
C: Active defense uses controlled defensive measures; honeypots deliberately attract or observe adversary activity in instrumented decoy systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to choose a hunting scope based on risky configuration or business-critical assets.
D: Organized criminal groups commonly pursue financial gain through fraud, extortion, theft, or illicit services. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to choose a hunting scope based on risky configuration or business-critical assets.
E: Useful intelligence is evaluated for timeliness, relevance, and accuracy before analysts act on it. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to choose a hunting scope based on risky configuration or business-critical assets.
Learning point: Use Threat-hunting focus areas when the key requirement is to choose a hunting scope based on risky configuration or business-critical assets.
Lucerne Publishing is designing a combined control. It must deploy a monitored decoy to collect attacker behavior with minimal production risk, and investigate compromise introduced through a trusted vendor or software dependency. Which TWO options are most appropriate? Select based on the scenario’s decisive constraint, not on which technology is newest.
Correct answers: C, D
Why: Supply-chain compromise targets trusted vendors, software, updates, dependencies, or service providers to reach downstream victims. It directly fits this scenario because the requirement is to investigate compromise introduced through a trusted vendor or software dependency. Active defense uses controlled defensive measures; honeypots deliberately attract or observe adversary activity in instrumented decoy systems. It directly fits this scenario because the requirement is to deploy a monitored decoy to collect attacker behavior with minimal production risk.
Option review:
A: Organized criminal groups commonly pursue financial gain through fraud, extortion, theft, or illicit services. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to deploy a monitored decoy to collect attacker behavior with minimal production risk; investigate compromise introduced through a trusted vendor or software dependency.
B: Nation-state actors pursue geopolitical, intelligence, military, or strategic national objectives and may have substantial resources. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to deploy a monitored decoy to collect attacker behavior with minimal production risk; investigate compromise introduced through a trusted vendor or software dependency.
C: Supply-chain compromise targets trusted vendors, software, updates, dependencies, or service providers to reach downstream victims. It directly fits this scenario because the requirement is to investigate compromise introduced through a trusted vendor or software dependency.
D: Active defense uses controlled defensive measures; honeypots deliberately attract or observe adversary activity in instrumented decoy systems. It directly fits this scenario because the requirement is to deploy a monitored decoy to collect attacker behavior with minimal production risk.
E: A script kiddie relies heavily on existing tools or exploits with limited technical depth. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to deploy a monitored decoy to collect attacker behavior with minimal production risk; investigate compromise introduced through a trusted vendor or software dependency.
Learning point: Use Active defense and honeypots, Supply-chain threat when the key requirement is to deploy a monitored decoy to collect attacker behavior with minimal production risk; investigate compromise introduced through a trusted vendor or software dependency.
During a security review, a vulnerability analyst must address two separate needs: characterize a highly resourced adversary maintaining long-term access, and describe recurring adversary behavior patterns rather than a single indicator. Select TWO. Assume the activity is authorized and must follow normal enterprise change control.
Correct answers: B, D
Why: TTPs describe how adversaries pursue objectives and can help analysts connect behavior across incidents. It directly fits this scenario because the requirement is to describe recurring adversary behavior patterns rather than a single indicator. An APT is a capable, persistent adversary that pursues strategic objectives over an extended period. It directly fits this scenario because the requirement is to characterize a highly resourced adversary maintaining long-term access.
Option review:
A: Insider threats arise from people with legitimate access and may be intentional or unintentional. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a highly resourced adversary maintaining long-term access; describe recurring adversary behavior patterns rather than a single indicator.
B: TTPs describe how adversaries pursue objectives and can help analysts connect behavior across incidents. It directly fits this scenario because the requirement is to describe recurring adversary behavior patterns rather than a single indicator.
C: Supply-chain compromise targets trusted vendors, software, updates, dependencies, or service providers to reach downstream victims. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a highly resourced adversary maintaining long-term access; describe recurring adversary behavior patterns rather than a single indicator.
D: An APT is a capable, persistent adversary that pursues strategic objectives over an extended period. It directly fits this scenario because the requirement is to characterize a highly resourced adversary maintaining long-term access.
E: A script kiddie relies heavily on existing tools or exploits with limited technical depth. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a highly resourced adversary maintaining long-term access; describe recurring adversary behavior patterns rather than a single indicator.
Learning point: Use Advanced persistent threat (APT), Tactics, techniques, and procedures (TTPs) when the key requirement is to characterize a highly resourced adversary maintaining long-term access; describe recurring adversary behavior patterns rather than a single indicator.
an OT security analyst at City Power Utilities is comparing several approaches. The deciding requirement is to characterize an attacker motivated by public advocacy or ideology. Which option should be chosen? Assume no additional product-specific features are available beyond the concepts listed.
Correct answer: C
Why: Hacktivists are primarily motivated by ideological, political, or social causes. It directly fits this scenario because the requirement is to characterize an attacker motivated by public advocacy or ideology.
Option review:
A: Nation-state actors pursue geopolitical, intelligence, military, or strategic national objectives and may have substantial resources. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize an attacker motivated by public advocacy or ideology.
B: Hunting can prioritize misconfigurations, isolated networks, business-critical assets, and high-value processes based on risk. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize an attacker motivated by public advocacy or ideology.
C: Hacktivists are primarily motivated by ideological, political, or social causes. It directly fits this scenario because the requirement is to characterize an attacker motivated by public advocacy or ideology.
D: Insider threats arise from people with legitimate access and may be intentional or unintentional. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize an attacker motivated by public advocacy or ideology.
E: A script kiddie relies heavily on existing tools or exploits with limited technical depth. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize an attacker motivated by public advocacy or ideology.
Learning point: Use Hacktivist when the key requirement is to characterize an attacker motivated by public advocacy or ideology.
While supporting a newly acquired subsidiary, a security consultant is asked to characterize a coordinated threat group driven primarily by profit. Which concept or tool is the clearest match? The organization wants a vendor-neutral approach that can be explained during audit review.
Correct answer: B
Why: Organized criminal groups commonly pursue financial gain through fraud, extortion, theft, or illicit services. It directly fits this scenario because the requirement is to characterize a coordinated threat group driven primarily by profit.
Option review:
A: Active defense uses controlled defensive measures; honeypots deliberately attract or observe adversary activity in instrumented decoy systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a coordinated threat group driven primarily by profit.
B: Organized criminal groups commonly pursue financial gain through fraud, extortion, theft, or illicit services. It directly fits this scenario because the requirement is to characterize a coordinated threat group driven primarily by profit.
C: Indicators of compromise must be collected, validated, analyzed in context, and applied to searches or detections. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a coordinated threat group driven primarily by profit.
D: A script kiddie relies heavily on existing tools or exploits with limited technical depth. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a coordinated threat group driven primarily by profit.
E: Closed sources include paid feeds, information-sharing groups, and internal organizational data. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a coordinated threat group driven primarily by profit.
Learning point: Use Organized cybercrime when the key requirement is to characterize a coordinated threat group driven primarily by profit.
Northwind Traders is designing a combined control. It must characterize an adversary conducting operations for national strategic interests, and use subscription, sharing-community, or internal-only intelligence. Which TWO options are most appropriate? Base the decision on the primary security requirement, not on implementation convenience.
Correct answers: B, D
Why: Closed sources include paid feeds, information-sharing groups, and internal organizational data. It directly fits this scenario because the requirement is to use subscription, sharing-community, or internal-only intelligence. Nation-state actors pursue geopolitical, intelligence, military, or strategic national objectives and may have substantial resources. It directly fits this scenario because the requirement is to characterize an adversary conducting operations for national strategic interests.
Option review:
A: TTPs describe how adversaries pursue objectives and can help analysts connect behavior across incidents. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize an adversary conducting operations for national strategic interests; use subscription, sharing-community, or internal-only intelligence.
B: Closed sources include paid feeds, information-sharing groups, and internal organizational data. It directly fits this scenario because the requirement is to use subscription, sharing-community, or internal-only intelligence.
C: A script kiddie relies heavily on existing tools or exploits with limited technical depth. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize an adversary conducting operations for national strategic interests; use subscription, sharing-community, or internal-only intelligence.
D: Nation-state actors pursue geopolitical, intelligence, military, or strategic national objectives and may have substantial resources. It directly fits this scenario because the requirement is to characterize an adversary conducting operations for national strategic interests.
E: Useful intelligence is evaluated for timeliness, relevance, and accuracy before analysts act on it. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize an adversary conducting operations for national strategic interests; use subscription, sharing-community, or internal-only intelligence.
Learning point: Use Nation-state actor, Closed-source intelligence when the key requirement is to characterize an adversary conducting operations for national strategic interests; use subscription, sharing-community, or internal-only intelligence.
During a security review, a cloud security analyst must address two separate needs: characterize a low-skill attacker using readily available tools without deep understanding, and route relevant intelligence to teams that can change controls, priorities, and detections. Select TWO. The environment follows least privilege and preserves evidence where incident handling is involved.
Correct answers: B, D
Why: A script kiddie relies heavily on existing tools or exploits with limited technical depth. It directly fits this scenario because the requirement is to characterize a low-skill attacker using readily available tools without deep understanding. Threat intelligence should inform incident response, vulnerability management, risk management, security engineering, and detection teams. It directly fits this scenario because the requirement is to route relevant intelligence to teams that can change controls, priorities, and detections.
Option review:
A: Hunting can prioritize misconfigurations, isolated networks, business-critical assets, and high-value processes based on risk. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a low-skill attacker using readily available tools without deep understanding; route relevant intelligence to teams that can change controls, priorities, and detections.
B: A script kiddie relies heavily on existing tools or exploits with limited technical depth. It directly fits this scenario because the requirement is to characterize a low-skill attacker using readily available tools without deep understanding.
C: Supply-chain compromise targets trusted vendors, software, updates, dependencies, or service providers to reach downstream victims. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a low-skill attacker using readily available tools without deep understanding; route relevant intelligence to teams that can change controls, priorities, and detections.
D: Threat intelligence should inform incident response, vulnerability management, risk management, security engineering, and detection teams. It directly fits this scenario because the requirement is to route relevant intelligence to teams that can change controls, priorities, and detections.
E: An APT is a capable, persistent adversary that pursues strategic objectives over an extended period. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to characterize a low-skill attacker using readily available tools without deep understanding; route relevant intelligence to teams that can change controls, priorities, and detections.
Learning point: Use Script kiddie, Cross-functional intelligence sharing when the key requirement is to characterize a low-skill attacker using readily available tools without deep understanding; route relevant intelligence to teams that can change controls, priorities, and detections.
At Coho Winery, a systems security analyst needs to assess risk from a trusted user who misuses access deliberately or accidentally. Which option is the BEST fit for a branch-office network? Use the choice that most directly addresses the stated evidence rather than a broader control.
Correct answer: A
Why: Insider threats arise from people with legitimate access and may be intentional or unintentional. It directly fits this scenario because the requirement is to assess risk from a trusted user who misuses access deliberately or accidentally.
Option review:
A: Insider threats arise from people with legitimate access and may be intentional or unintentional. It directly fits this scenario because the requirement is to assess risk from a trusted user who misuses access deliberately or accidentally.
B: A script kiddie relies heavily on existing tools or exploits with limited technical depth. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to assess risk from a trusted user who misuses access deliberately or accidentally.
C: TTPs describe how adversaries pursue objectives and can help analysts connect behavior across incidents. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to assess risk from a trusted user who misuses access deliberately or accidentally.
D: Supply-chain compromise targets trusted vendors, software, updates, dependencies, or service providers to reach downstream victims. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to assess risk from a trusted user who misuses access deliberately or accidentally.
E: Hunting can prioritize misconfigurations, isolated networks, business-critical assets, and high-value processes based on risk. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to assess risk from a trusted user who misuses access deliberately or accidentally.
Learning point: Use Insider threat when the key requirement is to assess risk from a trusted user who misuses access deliberately or accidentally.
During an investigation at Litware Manufacturing, the immediate requirement is to investigate compromise introduced through a trusted vendor or software dependency. What should an incident responder select? The team wants the most defensible analyst action before expanding the investigation.
Correct answer: B
Why: Supply-chain compromise targets trusted vendors, software, updates, dependencies, or service providers to reach downstream victims. It directly fits this scenario because the requirement is to investigate compromise introduced through a trusted vendor or software dependency.
Option review:
A: Active defense uses controlled defensive measures; honeypots deliberately attract or observe adversary activity in instrumented decoy systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to investigate compromise introduced through a trusted vendor or software dependency.
B: Supply-chain compromise targets trusted vendors, software, updates, dependencies, or service providers to reach downstream victims. It directly fits this scenario because the requirement is to investigate compromise introduced through a trusted vendor or software dependency.
C: Open sources include public social media, blogs, forums, government bulletins, CERT/CSIRT notices, and portions of the deep or dark web. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to investigate compromise introduced through a trusted vendor or software dependency.
D: Organized criminal groups commonly pursue financial gain through fraud, extortion, theft, or illicit services. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to investigate compromise introduced through a trusted vendor or software dependency.
E: Hunting can prioritize misconfigurations, isolated networks, business-critical assets, and high-value processes based on risk. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to investigate compromise introduced through a trusted vendor or software dependency.
Learning point: Use Supply-chain threat when the key requirement is to investigate compromise introduced through a trusted vendor or software dependency.
Fourth Coffee is updating its security operations standard for a multi-site enterprise. Which option most directly helps the team describe recurring adversary behavior patterns rather than a single indicator? Select based on the scenario’s decisive constraint, not on which technology is newest.
Correct answer: E
Why: TTPs describe how adversaries pursue objectives and can help analysts connect behavior across incidents. It directly fits this scenario because the requirement is to describe recurring adversary behavior patterns rather than a single indicator.
Option review:
A: Hacktivists are primarily motivated by ideological, political, or social causes. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to describe recurring adversary behavior patterns rather than a single indicator.
B: Active defense uses controlled defensive measures; honeypots deliberately attract or observe adversary activity in instrumented decoy systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to describe recurring adversary behavior patterns rather than a single indicator.
C: Indicators of compromise must be collected, validated, analyzed in context, and applied to searches or detections. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to describe recurring adversary behavior patterns rather than a single indicator.
D: Nation-state actors pursue geopolitical, intelligence, military, or strategic national objectives and may have substantial resources. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to describe recurring adversary behavior patterns rather than a single indicator.
E: TTPs describe how adversaries pursue objectives and can help analysts connect behavior across incidents. It directly fits this scenario because the requirement is to describe recurring adversary behavior patterns rather than a single indicator.
Learning point: Use Tactics, techniques, and procedures (TTPs) when the key requirement is to describe recurring adversary behavior patterns rather than a single indicator.
For a customer-facing messaging service, a response lead must satisfy all three needs: decide whether a threat report is current, applicable, and trustworthy enough to use; choose a hunting scope based on risky configuration or business-critical assets; and characterize an adversary conducting operations for national strategic interests. Select THREE. Assume the activity is authorized and must follow normal enterprise change control.
Correct answers: A, B, D
Why: Hunting can prioritize misconfigurations, isolated networks, business-critical assets, and high-value processes based on risk. It directly fits this scenario because the requirement is to choose a hunting scope based on risky configuration or business-critical assets. Useful intelligence is evaluated for timeliness, relevance, and accuracy before analysts act on it. It directly fits this scenario because the requirement is to decide whether a threat report is current, applicable, and trustworthy enough to use. Nation-state actors pursue geopolitical, intelligence, military, or strategic national objectives and may have substantial resources. It directly fits this scenario because the requirement is to characterize an adversary conducting operations for national strategic interests.
Option review:
A: Hunting can prioritize misconfigurations, isolated networks, business-critical assets, and high-value processes based on risk. It directly fits this scenario because the requirement is to choose a hunting scope based on risky configuration or business-critical assets.
B: Useful intelligence is evaluated for timeliness, relevance, and accuracy before analysts act on it. It directly fits this scenario because the requirement is to decide whether a threat report is current, applicable, and trustworthy enough to use.
C: TTPs describe how adversaries pursue objectives and can help analysts connect behavior across incidents. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to decide whether a threat report is current, applicable, and trustworthy enough to use; choose a hunting scope based on risky configuration or business-critical assets; characterize an adversary conducting operations for national strategic interests.
D: Nation-state actors pursue geopolitical, intelligence, military, or strategic national objectives and may have substantial resources. It directly fits this scenario because the requirement is to characterize an adversary conducting operations for national strategic interests.
E: Open sources include public social media, blogs, forums, government bulletins, CERT/CSIRT notices, and portions of the deep or dark web. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to decide whether a threat report is current, applicable, and trustworthy enough to use; choose a hunting scope based on risky configuration or business-critical assets; characterize an adversary conducting operations for national strategic interests.
Learning point: Use Threat-intelligence confidence, Threat-hunting focus areas, Nation-state actor when the key requirement is to decide whether a threat report is current, applicable, and trustworthy enough to use; choose a hunting scope based on risky configuration or business-critical assets; characterize an adversary conducting operations for national strategic interests.
Popular posts
Recent Posts
