312-85 · Question #17
ABC is a well-established cyber-security company in the United States. The organization implemented the automation of tasks such as data enrichment and indicator aggregation. They also joined…
The correct answer is A. Level 2: increasing CTI capabilities. Option A is correct because ABC exhibits the hallmark characteristics of Level 2 on the threat intelligence maturity model: they have implemented automation (data enrichment, indicator aggregation) and engage in threat-sharing communities - both signs of growing CTI capability…
Question
ABC is a well-established cyber-security company in the United States. The organization implemented the automation of tasks such as data enrichment and indicator aggregation. They also joined various communities to increase their knowledge about the emerging threats. However, the security teams can only detect and prevent identified threats in a reactive approach. Based on threat intelligence maturity model, identify the level of ABC to know the stage at which the organization stands with its security and vulnerabilities.
Options
- ALevel 2: increasing CTI capabilities
- BLevel 3: CTI program in place
- CLevel 1: preparing for CTI
- DLevel 0: vague where to start
How the community answered
(66 responses)- A73% (48)
- B5% (3)
- C9% (6)
- D14% (9)
Explanation
Option A is correct because ABC exhibits the hallmark characteristics of Level 2 on the threat intelligence maturity model: they have implemented automation (data enrichment, indicator aggregation) and engage in threat-sharing communities - both signs of growing CTI capability - yet remain reactive, only responding to already-identified threats rather than proactively hunting unknown ones.
Why the distractors are wrong:
- C (Level 1) is wrong because Level 1 organizations are just beginning to build foundational CTI practices with minimal tooling; ABC has already moved past that by establishing automation and community participation.
- B (Level 3) is wrong because a Level 3 organization has a full CTI program that enables proactive, predictive threat intelligence - ABC's purely reactive posture disqualifies it.
- D (Level 0) is wrong because Level 0 represents no CTI direction whatsoever; ABC clearly has structured processes and community involvement.
Memory tip: Think of the levels as a ladder - automation + community = Level 2, but reactive = not yet Level 3. The key differentiator between L2 and L3 is the shift from reactive (responding to known threats) to proactive (anticipating unknown ones). If the organization is still waiting to be told what the threat is, it's capped at Level 2.
Topics
Community Discussion
No community discussion yet for this question.