312-85 · Question #12
Alice, an analyst, shared information with security operation managers and network operations center (NOC) staff for protecting the organizational resources against various threats. Information…
The correct answer is B. Tactical threat intelligence. Tactical threat intelligence (B) is correct because it focuses specifically on the how of adversary behavior - threat actor TTPs (Tactics, Techniques, and Procedures), malware campaigns, and tools - and is designed for security operations audiences like SOC/NOC staff who need…
Question
Alice, an analyst, shared information with security operation managers and network operations center (NOC) staff for protecting the organizational resources against various threats. Information shared by Alice was highly technical and include threat actor TTPs, malware campaigns, tools used by threat actors, and so on. Which of the following types of threat intelligence was shared by Alice?
Options
- AStrategic threat intelligence
- BTactical threat intelligence
- CTechnical threat intelligence
- DOperational threat intelligence
How the community answered
(48 responses)- A4% (2)
- B94% (45)
- C2% (1)
Explanation
Tactical threat intelligence (B) is correct because it focuses specifically on the how of adversary behavior - threat actor TTPs (Tactics, Techniques, and Procedures), malware campaigns, and tools - and is designed for security operations audiences like SOC/NOC staff who need to detect and respond to threats day-to-day.
Strategic (A) is wrong because it is high-level, non-technical intelligence for executives and decision-makers, covering broad trends and business risk rather than technical attack methods.
Technical (C) is wrong because technical intelligence deals with specific, machine-readable Indicators of Compromise (IoCs) such as IP addresses, file hashes, and domain names - not TTPs and campaign analysis.
Operational (D) is wrong because operational intelligence covers specific, imminent attack details - the who, when, and where of a planned campaign - rather than general TTP and tooling knowledge.
Memory tip: Think Tactical = TTPs. When you see TTPs mentioned alongside a security operations audience, it's always tactical. If it's for the C-suite, it's strategic; if it's raw IoCs for machines, it's technical; if it's "attack incoming Tuesday at 3am," it's operational.
Topics
Community Discussion
No community discussion yet for this question.