CompTIA CySA+ (CS0-003)Security OperationsMedium
A threat intelligence analyst rates an external feed source as 'B2' when logging a new indicator, meaning the source is usually reliable and the information is probably true. Which evaluation system is being used to grade the source and the information?
- AMITRE ATT&CK Navigator
- BSTIX confidence levels
- CTraffic Light Protocol (TLP)
- DAdmiralty Code
Show answer & explanationAnswer & explanation
Correct answer: D. Admiralty Code
The Admiralty Code (also called the NATO System) grades intelligence using a letter (A-F) for source reliability and a number (1-6) for information credibility, so 'B2' means a usually reliable source providing probably true information. STIX confidence levels are numeric scores in threat intel objects, MITRE ATT&CK Navigator visualizes adversary techniques, and TLP governs how information may be shared rather than its reliability.
Why the other options are wrong
- A. ATT&CK Navigator is a visualization tool for techniques, not a source reliability scale.
- B. STIX confidence is typically a single numeric value, not a letter-number combination.
- C. TLP (White/Green/Amber/Red) controls dissemination, not reliability grading.
Admiralty Code
A two-part rating system used to evaluate intelligence: a letter (A-F) rates source reliability, and a number (1-6) rates the credibility of the information itself.
- A=Completely reliable through F=Reliability cannot be judged
- 1=Confirmed through 6=Cannot be judged
- Widely used in military and cyber threat intelligence to grade feeds
Memory trick: 'Admiralty grades intel like a report card: letter for source, number for truth.'