AI-Assisted Threat Actor Profiling
Final Quiz
Connecting to LMS...
Progress: in progress
Assessment
1. What is the safest purpose of threat actor profiling?
A. Supporting defensive decisions by understanding likely behaviors, objectives, capabilities, targeting, and tradecraft.
B. Publicly accusing individuals without evidence.
C. Replacing incident response.
D. Conducting unauthorized retaliation.
2. What is AI best used for in threat actor profiling?
A. Automatically proving attribution.
B. Generating accusations without sources.
C. Summarizing evidence, clustering observations, drafting profiles, and identifying analytic gaps.
D. Replacing source validation.
3. Why should scope be defined before profiling begins?
A. Scope makes evidence unnecessary.
B. Scope clarifies the intelligence question, authorized data sources, defensive purpose, and boundaries.
C. Scope allows collection of any private information.
D. Scope replaces analyst review.
4. What should responsible profiling avoid?
A. Corroboration.
B. Confidence levels.
C. Source references.
D. Doxxing, harassment, vigilantism, or unsupported accusations.
5. What is source provenance?
A. The source or evidence trail behind a claim, observation, or analytic judgment.
B. A password reset method.
C. A user interface theme.
D. A backup schedule.
6. Which source can support defensive threat actor profiling?
A. Unsupported rumors only.
B. Internal telemetry, incident reports, vendor intelligence, advisories, open-source reporting, and validated case notes.
C. Invented indicators.
D. Private data collected without authorization.
7. Why should actor objectives be inferred cautiously?
A. Motive is always obvious.
B. AI can always determine intent perfectly.
C. Motive and intent are usually inferred from evidence and can be misread or oversimplified.
D. Objectives do not affect defensive planning.
8. What are TTPs?
A. A graphics format.
B. A password policy.
C. A legal contract.
D. Tactics, techniques, and procedures that describe behavior patterns.
9. Why are behavior patterns often more useful than labels alone?
A. Behavior can support detection, comparison, and defensive planning even when attribution is uncertain.
B. Labels always prove attribution.
C. Labels replace evidence.
D. Behavior is irrelevant to threat intelligence.
10. Why should indicators such as domains or IP addresses not be over-weighted?
A. They always identify the actor conclusively.
B. They replace TTP analysis.
C. They can be reused, shared, spoofed, short-lived, or misleading without broader context.
D. They are never useful.
11. What is an AI-assisted timeline useful for?
A. Proving every hypothesis automatically.
B. Organizing events, observations, source dates, campaign phases, and analytic gaps.
C. Removing uncertainty.
D. Replacing incident evidence.
12. Why should AI-generated claims keep source references?
A. Sources make reports less accurate.
B. AI claims are evidence by themselves.
C. Source references are only decorative.
D. Reviewers need to trace claims back to evidence and evaluate reliability.
13. What is circular reporting?
A. Multiple sources repeating the same original claim without independent verification.
B. A confirmed fact from many independent sources.
C. A malware command pattern.
D. A network routing loop only.
14. What is confirmation bias?
A. A method for improving source reliability automatically.
B. A type of encryption.
C. A tendency to favor evidence that supports an existing belief while discounting contrary information.
D. A guaranteed attribution technique.
15. What should a responsible threat actor profile separate?
A. Evidence from all source references.
B. Facts, assumptions, hypotheses, analytic judgments, confidence levels, and unknowns.
C. Defensive conclusions from context.
D. Intelligence needs from reporting.
16. Which statement best summarizes AI-assisted threat actor profiling?
A. AI proves attribution without evidence.
B. Profiling should focus on public accusation.
C. Indicators alone are always enough.
D. AI can help organize and explain evidence, but human analysts must validate sources, manage uncertainty, avoid bias, and report responsibly.
Submit Quiz
Previous