CREST Practitioner Threat Intelligence Analyst Sample Questions:
1. Rinni is an incident handler and she is performing memory dump analysis.
Which of following tools she can use in order to perform memory dump analysis?
A) iNetSim
B) Procmon and ProcessExplorer
C) Scylla and OllyDumpEx
D) OllyDbg and IDA Pro
2. Eric works as an incident handler at Erinol software systems. He was assigned a task to protect the organization from any kind of DoS/DDoS attacks.
Which of the following tools can be used by Eric to achieve his objective?
A) Incapsula
B) IDA
C) Hydra
D) Wireshark
3. Cybersol Technologies initiated a cyber-threat intelligence program with a team of threat intelligence analysts. During the process, the analysts started converting the raw data into useful information by applying various techniques, such as machine-based techniques, and statistical methods.
In which of the following phases of the threat intelligence lifecycle is the threat intelligence team currently working?
A) Planning and direction
B) Processing and exploitation
C) Dissemination and integration
D) Analysis and production
4. During the process of detecting and containing malicious emails, incident responders should examine the originating IP address of the emails.
The steps to examine the originating IP address are as follow:
1. Search for the IP in the WHOIS database
2. Open the email to trace and find its header
3. Collect the IP address of the sender from the header of the received mail
4. Look for the geographic address of the sender in the WHOIS database
Identify the correct sequence of steps to be performed by the incident responders to examine originating IP address of the emails.
A) 4-->1-->2-->3
B) 1-->3-->2-->4
C) 2-->1-->4-->3
D) 2-->3-->1-->4
5. Alison, an analyst in an XYZ organization, wants to retrieve information about a company's website from the time of its inception as well as the removed information from the target website.
What should Alison do to get the information he needs.
A) Alison should recover cached pages of the website from the Google search engine cache to extract the required website information.
B) Alison should run the Web Data Extractor tool to extract the required website information.
C) Alison should use SmartWhois to extract the required website information.
D) Alison should use https://archive.org to extract the required website information.
Solutions:
| Question # 1 Answer: C | Question # 2 Answer: A | Question # 3 Answer: B | Question # 4 Answer: D | Question # 5 Answer: D |
We're so confident of our products that we provide no hassle product exchange.


By Louis

