nerdexam
EC-Council

312-85 · Question #20

Sarah is a security operations center (SOC) analyst working at JW Williams and Sons organization based in Chicago. As a part of security operations, she contacts information providers (sharing…

The correct answer is C. Providers of comprehensive cyber-threat intelligence. Providers of comprehensive cyber-threat intelligence (C) is correct because Sarah receives a complete package: validated/prioritized threat indicators plus in-depth technical analysis of malware, botnets, DDoS methods, and malicious tools, usable across both tactical and…

Threat Intelligence Feeds and Sources

Question

Sarah is a security operations center (SOC) analyst working at JW Williams and Sons organization based in Chicago. As a part of security operations, she contacts information providers (sharing partners) for gathering information such as collections of validated and prioritized threat indicators along with a detailed technical analysis of malware samples, botnets, DDoS attack methods, and various other malicious tools. She further used the collected information at the tactical and operational levels. Sarah obtained the required information from which of the following types of sharing partner?

Options

  • AProviders of threat data feeds
  • BProviders of threat indicators
  • CProviders of comprehensive cyber-threat intelligence
  • DProviders of threat actors

How the community answered

(59 responses)
  • A
    19% (11)
  • B
    3% (2)
  • C
    71% (42)
  • D
    7% (4)

Explanation

Providers of comprehensive cyber-threat intelligence (C) is correct because Sarah receives a complete package: validated/prioritized threat indicators plus in-depth technical analysis of malware, botnets, DDoS methods, and malicious tools, usable across both tactical and operational levels - that breadth of coverage defines "comprehensive."

Option A (threat data feeds) is wrong because data feeds deliver raw, automated streams of threat data (e.g., IP blocklists) without validation, prioritization, or the technical analysis Sarah is receiving. Option B (threat indicators) falls short because it covers only IOCs (hashes, IPs, domains) - not the detailed malware or botnet analysis described. Option D (threat actors) is not a recognized provider category; threat actor profiling is one component of intelligence, not a distinct type of sharing partner.

Memory tip: Use the word "comprehensive" as your anchor - if the intelligence bundle includes both indicators and deep technical analysis usable at multiple operational levels, it's comprehensive CTI. If it's just raw feeds → A; just indicators → B; just actor profiles → D.

Topics

#threat intelligence sources#threat indicators#comprehensive cyber intelligence#intelligence sharing

Community Discussion

No community discussion yet for this question.

Full 312-85 Practice