312-85 · Question #10
A network administrator working in an ABC organization collected log files generated by a traffic monitoring system, which may not seem to have useful information, but after performing proper…
The correct answer is D. Low-level data. Low-level data refers to raw, unprocessed information - like log files, packet captures, and event records - that lacks immediate context but becomes valuable after analysis. Log files from a traffic monitoring system are exactly this: voluminous, seemingly mundane data that…
Question
A network administrator working in an ABC organization collected log files generated by a traffic monitoring system, which may not seem to have useful information, but after performing proper analysis by him, the same information can be used to detect an attack in the network. Which of the following categories of threat information has he collected?
Options
- AAdvisories
- BStrategic reports
- CDetection indicators
- DLow-level data
How the community answered
(22 responses)- A9% (2)
- B5% (1)
- C14% (3)
- D73% (16)
Explanation
Low-level data refers to raw, unprocessed information - like log files, packet captures, and event records - that lacks immediate context but becomes valuable after analysis. Log files from a traffic monitoring system are exactly this: voluminous, seemingly mundane data that requires expert interpretation to surface attack indicators.
Why the distractors are wrong:
- A. Advisories are curated notifications from vendors or CERTs warning about specific vulnerabilities or threats - pre-analyzed, not raw.
- B. Strategic reports are high-level intelligence documents for decision-makers about threat actor trends and business risk - far above raw logs.
- C. Detection indicators (IOCs like IPs, hashes, domains) are already-processed artifacts extracted from low-level data - they are the output of analysis, not the raw input.
Memory tip: Think of the threat intelligence pyramid - low-level data sits at the base (high volume, low value alone), while advisories and strategic reports sit higher (low volume, high value). If the question describes raw, unprocessed sources like logs or packet captures that "don't seem useful" without analysis, that's always low-level data.
Topics
Community Discussion
No community discussion yet for this question.