312-50V12 · Question #290
Roma is a member of a security team. She was tasked with protecting the internal network of an organization from imminent threats. To accomplish this task, Roma fed threat intelligence into the…
The correct answer is D. Technical threat intelligence. Roma is using Technical Threat Intelligence, which involves machine-readable data fed directly into security devices to automatically block malicious traffic. This type of intelligence is operationalized at the technical layer of security infrastructure.
Question
Options
- AOperational threat intelligence
- BStrategic threat intelligence
- CTactical threat intelligence
- DTechnical threat intelligence
How the community answered
(23 responses)- B4% (1)
- D96% (22)
Why each option
Roma is using Technical Threat Intelligence, which involves machine-readable data fed directly into security devices to automatically block malicious traffic. This type of intelligence is operationalized at the technical layer of security infrastructure.
Operational threat intelligence focuses on the details of specific incoming cyberattacks, campaigns, or threat actor TTPs to help security teams understand the nature and timing of attacks, not to feed automated blocking rules into security devices.
Strategic threat intelligence is high-level, human-readable information intended for executive and management audiences to support business decisions and risk management, not for direct input into technical security devices.
Tactical threat intelligence focuses on threat actors' tactics, techniques, and procedures (TTPs) to help security teams understand how attackers operate and improve defenses strategically, rather than feeding machine-readable indicators into devices for automated blocking.
Technical threat intelligence consists of specific, machine-readable indicators of compromise (IoCs) such as malicious IP addresses, URLs, file hashes, and domain names that are ingested directly into security devices like firewalls, IDS/IPS, and SIEMs in digital format. This type of intelligence is consumed by automated systems rather than humans and is used specifically to block or identify inbound and outbound malicious traffic in real time. The key distinguishing factor is the digital/automated feeding of data into security tools to take immediate defensive action.
Concept tested: Types of threat intelligence and their technical applications
Source: https://www.cisa.gov/sites/default/files/publications/CISA-Cyber-Threat-Intelligence-Sharing.pdf
Topics
Community Discussion
No community discussion yet for this question.