Start Here
Five review stations, each a different way to practice Chapter 2. Work through them in any order. Nothing here is graded or stored, so use it as many times as you like before the quiz or the exam.
What this chapter asked you to be able to do
- Tell apart a threat, a vulnerability, and a risk, and explain how a threat becomes a risk when it can exploit a weakness in your environment.
- Identify sources of threat intelligence (OSINT, commercial feeds, ISACs, government agencies, and IoC feeds) and interpret indicators of compromise.
- Explain the Common Vulnerability Scoring System (CVSS), its base, temporal, and environmental metrics, and its five severity ratings.
- Categorize threat actors by type, capability, and motivation, and explain how internal positioning raises threat severity.
- Analyze an attack scenario to determine the likely actor type and motivation from observable characteristics.
Your progress this session
These counters update as you check answers on each station. They reset when you reload the page.
Key Terms Flashcards
Select a card to reveal its definition, then select again to flip it back. Try to state the definition before you flip. The counter tracks how many distinct cards you have opened.
Matching Scenarios to Threat Actor Types
Each threat actor type has a recognizable pattern of resources, targets, and behavior. Read each scenario and choose the actor type it best describes, then check your answer.
Identifying Threat Actor Motivations
Motivation predicts an attacker's targets, methods, and intensity. Read each scenario and choose the motivation that best explains the behavior, then check your answer.
Identifying Threat Intelligence Sources and Concepts
Threat intelligence comes from several channels, each with its own strengths and limits. Read each description and choose the source or concept it defines, then check your answer.
Reference: CVSS severity ratings
| CVSS score | Severity rating |
|---|---|
| 0.0 | None |
| 0.1 to 3.9 | Low |
| 4.0 to 6.9 | Medium |
| 7.0 to 8.9 | High |
| 9.0 to 10.0 | Critical |
A score of 7.0 or higher typically triggers rapid patching decisions. Base metrics reflect inherent severity, temporal metrics account for exploit availability and patch status, and environmental metrics adjust for your organization's context.
Knowledge Check
Ten multiple-choice questions across the whole chapter. Answer them all, then select Score my answers for feedback and a final total.