300-220 · Question #36
Threat intelligence handling involves all of the following EXCEPT:
The correct answer is A. Programming new security tools. Programming new security tools is the correct exception because threat intelligence handling is a process focused on collecting, organizing, and applying existing information about threats - not on software development or tool creation. The distractors are all genuine…
Question
Threat intelligence handling involves all of the following EXCEPT:
Options
- AProgramming new security tools
- BGathering relevant data
- CCataloging information for easy access
- DUtilizing intelligence for defensive measures
How the community answered
(25 responses)- A88% (22)
- B8% (2)
- C4% (1)
Explanation
Programming new security tools is the correct exception because threat intelligence handling is a process focused on collecting, organizing, and applying existing information about threats - not on software development or tool creation.
The distractors are all genuine components of threat intelligence workflows: gathering relevant data (B) is the collection phase where raw threat indicators are acquired from feeds, dark web sources, or incident reports; cataloging information (C) refers to organizing that data into structured formats (threat databases, IOC repositories) so analysts can retrieve it efficiently; and utilizing intelligence for defensive measures (D) is the action phase where processed intelligence informs firewall rules, detection signatures, or incident response decisions.
Memory tip: Think of threat intelligence as a library system - you gather books (data), catalog them (organize), and read them to make decisions (utilize). Librarians don't build the printing press; they work with existing resources. Similarly, threat intel teams consume and apply information rather than build new tools.
Topics
Community Discussion
No community discussion yet for this question.