CompTIA CySA+ Practice Questions: Threat Intelligence

9 free, exam-style CompTIA CySA+ (CS0-003) practice questions covering Threat Intelligence. Each question shows the correct answer and a clear explanation. Ready for the real thing? Take the full timed quiz below.

🚀 Take the full CompTIA CySA+ quiz 📘 CompTIA CySA+ study guide

Q1. What is the PRIMARY purpose of the MITRE ATT&CK framework? (Q-628018)

Explanation: MITRE ATT&CK provides a knowledge base of real-world adversary behaviors. Learn more.

Q2. What does TTP stand for in threat intelligence? (Q-628019)

Explanation: TTPs describe how adversaries operate (e.g., initial access, persistence). Learn more.

Q3. What is the PRIMARY purpose of the Diamond Model of Intrusion Analysis? (Q-628024)

Explanation: The Diamond Model analyzes events via adversary, capability, infrastructure, and victim. Learn more.

Q4. What is the PRIMARY purpose of a threat intelligence platform (TIP)? (Q-628042)

Explanation: TIPs centralize threat feeds, IOCs, and analysis tools. Learn more.

Q5. What is the PRIMARY purpose of a threat intelligence platform (TIP)? (Q-628070)

Explanation: TIPs centralize threat feeds, IOCs, and analysis tools. Learn more.

Q6. What is the PRIMARY purpose of a threat intelligence platform (TIP)? (Q-628080)

Explanation: TIPs centralize threat feeds, IOCs, and analysis tools. Learn more.

Q7. Which threat intelligence standard is used for automating the exchange of cyber threat information?

Explanation: STIX (Structured Threat Information Expression) and TAXII (Trusted Automated Exchange of Intelligence Information) are standards for sharing threat intel. Learn more.

Q8. Why should threat intelligence indicators have expiration or review dates?

Explanation: Domains, IPs, and hashes can age out or be repurposed, so intelligence should be reviewed for relevance. Learn more.

Q9. Which kind of IOC is easiest for attackers to change and often has the shortest useful lifetime?

Explanation: IP addresses and domains are relatively easy for attackers to change, so they often age quickly. Learn more.

More CompTIA CySA+ practice topics