nerdexam
EC-Council

312-85 · Question #18

Alice, a threat intelligence analyst at HiTech Cyber Solutions, wants to gather information for identifying emerging threats to the organization and implement essential techniques to prevent their…

The correct answer is C. Hacking forums. Hacking forums (C) are the correct answer because they are underground online communities where threat actors openly discuss attack methodologies, tools, exploits, and post-attack cover-up techniques - exactly the TTPs (Tactics, Techniques, and Procedures) Alice needs for…

Threat Intelligence Feeds and Sources

Question

Alice, a threat intelligence analyst at HiTech Cyber Solutions, wants to gather information for identifying emerging threats to the organization and implement essential techniques to prevent their systems and networks from such attacks. Alice is searching for online sources to obtain information such as the method used to launch an attack, and techniques and tools used to perform an attack and the procedures followed for covering the tracks after an attack. Which of the following online sources should Alice use to gather such information?

Options

  • AFinancial services
  • BSocial network settings
  • CHacking forums
  • DJob sites

How the community answered

(35 responses)
  • A
    3% (1)
  • C
    94% (33)
  • D
    3% (1)

Explanation

Hacking forums (C) are the correct answer because they are underground online communities where threat actors openly discuss attack methodologies, tools, exploits, and post-attack cover-up techniques - exactly the TTPs (Tactics, Techniques, and Procedures) Alice needs for threat intelligence.

Why the distractors are wrong:

  • A (Financial services): These provide market data, fraud reports, and compliance information - not attack methodology details useful for proactive threat intelligence.
  • B (Social network settings): Social network settings are privacy/configuration options for individual users, not a source of threat intelligence data.
  • D (Job sites): Job postings can reveal technology stacks (useful for passive recon against a target), but they don't contain attacker TTPs or post-exploitation techniques.

Memory tip: Think of the acronym TTPs - Tactics, Techniques, and Procedures. The question asks specifically about how attacks are launched, what tools are used, and how tracks are covered. The only option where threat actors themselves describe these things in detail is hacking forums, since that's where they share and collaborate on attack tradecraft.

Topics

#Threat Intelligence Sources#Hacking Forums#Attack Intelligence#Information Gathering

Community Discussion

No community discussion yet for this question.

Full 312-85 Practice