In intelligence development, which activity is included?

Prepare for the SANS FOR508 Exam. Use flashcards and multiple-choice questions, each with hints and explanations. Maximize your readiness for the test!

Multiple Choice

In intelligence development, which activity is included?

Explanation:
Campaign identification is the activity you use in intelligence development because it focuses on organizing scattered observations into a single, coherent threat picture. Analysts look at multiple indicators—malware families, infrastructure, TTPs, victim profiles, and timing—to determine whether they’re part of the same adversary campaign. By identifying and defining that campaign, you can map objectives, capabilities, and the evolution of the operation, which helps anticipate next moves, prioritize defenses, and inform higher-level attribution. The other options are more about operational techniques than the analytic work of building intelligence. Bit mangling implies altering data at a low level, data decoy is about misleading with false data, and traffic shaping involves manipulating network traffic—none of which capture the process of recognizing and linking related activities into a campaign.

Campaign identification is the activity you use in intelligence development because it focuses on organizing scattered observations into a single, coherent threat picture. Analysts look at multiple indicators—malware families, infrastructure, TTPs, victim profiles, and timing—to determine whether they’re part of the same adversary campaign. By identifying and defining that campaign, you can map objectives, capabilities, and the evolution of the operation, which helps anticipate next moves, prioritize defenses, and inform higher-level attribution.

The other options are more about operational techniques than the analytic work of building intelligence. Bit mangling implies altering data at a low level, data decoy is about misleading with false data, and traffic shaping involves manipulating network traffic—none of which capture the process of recognizing and linking related activities into a campaign.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy