nerdexam
EC-Council

312-85 · Question #11

Sam works as an analyst in an organization named InfoTech Security. He was asked to collect information from various threat intelligence sources. In meeting the deadline, he forgot to verify the…

The correct answer is D. Sam did not use the proper technology to use or consume the information. Option D is correct because the core mistake was Sam's lack of a proper Threat Intelligence Platform (TIP) or equivalent tooling to ingest, validate, and filter threat data before use. A proper TIP automates source credibility scoring, deduplication, and noise reduction - had…

Threat Intelligence Tools and Platforms

Question

Sam works as an analyst in an organization named InfoTech Security. He was asked to collect information from various threat intelligence sources. In meeting the deadline, he forgot to verify the threat intelligence sources and used data from an open-source data provider, who offered it at a very low cost. Through it was beneficial at the initial stage but relying on such data providers can produce unreliable data and noise putting the organization network into risk. What mistake Sam did that led to this situation?

Options

  • ASam used unreliable intelligence sources.
  • BSam used data without context.
  • CSam did not use the proper standardization formats for representing threat data.
  • DSam did not use the proper technology to use or consume the information.

How the community answered

(26 responses)
  • A
    19% (5)
  • B
    12% (3)
  • C
    4% (1)
  • D
    65% (17)

Explanation

Option D is correct because the core mistake was Sam's lack of a proper Threat Intelligence Platform (TIP) or equivalent tooling to ingest, validate, and filter threat data before use. A proper TIP automates source credibility scoring, deduplication, and noise reduction - had Sam used one, it would have flagged the low-quality provider and prevented unreliable data from entering the organization's workflow, regardless of deadline pressure.

Why the distractors are wrong:

  • A describes a symptom, not the root cause - the source appeared unreliable because proper vetting technology wasn't in place to assess it.
  • B (data without context) is a separate threat intelligence challenge about enrichment and correlation, which isn't described in the scenario.
  • C (standardization formats like STIX/TAXII) relates to interoperability between systems, not source quality or noise filtering, which isn't the issue here.

Memory tip: Think of it this way - technology is the gatekeeper. If you don't have the right tool (TIP) to consume threat data, you can't reliably control what gets in, no matter the source. When an exam scenario involves noise, unverified sources, or data quality problems in threat intelligence, look for the answer pointing to the consumption/validation tooling, not just the source itself.

Topics

#source verification#data quality#threat intelligence platforms#data validation

Community Discussion

No community discussion yet for this question.

Full 312-85 Practice