nerdexam
Cisco

300-220 · Question #36

Threat intelligence handling involves all of the following EXCEPT:

The correct answer is A. Programming new security tools. Programming new security tools is the correct exception because threat intelligence handling is a process focused on collecting, organizing, and applying existing information about threats - not on software development or tool creation. The distractors are all genuine…

Threat Hunting Fundamentals

Question

Threat intelligence handling involves all of the following EXCEPT:

Options

  • AProgramming new security tools
  • BGathering relevant data
  • CCataloging information for easy access
  • DUtilizing intelligence for defensive measures

How the community answered

(25 responses)
  • A
    88% (22)
  • B
    8% (2)
  • C
    4% (1)

Explanation

Programming new security tools is the correct exception because threat intelligence handling is a process focused on collecting, organizing, and applying existing information about threats - not on software development or tool creation.

The distractors are all genuine components of threat intelligence workflows: gathering relevant data (B) is the collection phase where raw threat indicators are acquired from feeds, dark web sources, or incident reports; cataloging information (C) refers to organizing that data into structured formats (threat databases, IOC repositories) so analysts can retrieve it efficiently; and utilizing intelligence for defensive measures (D) is the action phase where processed intelligence informs firewall rules, detection signatures, or incident response decisions.

Memory tip: Think of threat intelligence as a library system - you gather books (data), catalog them (organize), and read them to make decisions (utilize). Librarians don't build the printing press; they work with existing resources. Similarly, threat intel teams consume and apply information rather than build new tools.

Topics

#Threat Intelligence#Data Gathering#Intelligence Cataloging#Defensive Operations

Community Discussion

No community discussion yet for this question.

Full 300-220 Practice