Threat Intelligence Flashcards

1
Q

Threat Intelligence

Facilitate risk management

A

Sources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Threat Intelligence Sources

Can reduce incident response time

A

Hardening

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Threat Intelligence Sources

  • adversary tactics, techniques and procedures (TTPP
  • Threat maps
    ie: geographical representations of malware outbreaks
A

Provide cybersecurity insight

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Threat Intelligence

Closed/proprietary

OSINT (open-source intelligence)
- gov reports
- media
- academic papers

A

Threat Intelligence Sources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Threat Intelligence

  • closed/proprietary
  • file/code repositories
    ie: GitHub
  • Vulnerability databases
    Common Vulnerabilities and Exposures (CVEs)
A

more threat intel sources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Threat Intelligence

Dark Web/dark net
- Tor n/w - Tor web browser
- encrypted anonymous connections
- not indexed by search engines
- Tor encryption and anonymity
- Journalists
- Law enforcement
- Gov informants

A

sources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Threat Intelligence Sharing

Exchange of cybersecurity intelligence (CI) between entities

A

Automated Indicator Sharing (AIS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Threat Intelligence Sharing

  • form of AIS
  • Data exchange format for cybersecurity intelligence
A

Structured Threat Information eXpression (STIX)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Threat Intelligence Sharing

  • like RSS feeds for threats
  • consists of TAXII servers and clients
  • real-time cyber intelligence feeds
A

Trusted Automated eXChange of Intelligence Information (TAXII)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Threat Intelligence

open-source intelligence - refers to public cybersecurity intelligence sources

A

OSINT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Threat Intelligence

Example of OSINT

A

Common Vulnerabilities and Exposures (CVE) dbase

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Threat Intelligence

Encrypted and anonymized internet access mechanism allowing access to unindexed content

A

Dark Web

How well did you know this?
1
Not at all
2
3
4
5
Perfectly