nerdexam
EC-Council

312-85 · Question #34

Bob, a threat analyst, works in an organization named TechTop. He was asked to collect intelligence to fulfil the needs and requirements of the Red Tam present within the organization. Which of the…

The correct answer is B. Intelligence on latest vulnerabilities, threat actors, and their tactics, techniques, and procedures. Option B is correct because a Red Team operates as a simulated adversary - they need actionable intelligence on current vulnerabilities, known threat actors, and their TTPs (Tactics, Techniques, and Procedures) so they can realistically emulate real-world attacks against their…

Introduction to Threat Intelligence

Question

Bob, a threat analyst, works in an organization named TechTop. He was asked to collect intelligence to fulfil the needs and requirements of the Red Tam present within the organization. Which of the following are the needs of a RedTeam?

Options

  • AIntelligence related to increased attacks targeting a particular software or operating system
  • BIntelligence on latest vulnerabilities, threat actors, and their tactics, techniques, and procedures
  • CIntelligence extracted latest attacks analysis on similar organizations, which includes details about
  • DIntelligence that reveals risks related to various strategic business decisions

How the community answered

(46 responses)
  • A
    4% (2)
  • B
    89% (41)
  • C
    2% (1)
  • D
    4% (2)

Explanation

Option B is correct because a Red Team operates as a simulated adversary - they need actionable intelligence on current vulnerabilities, known threat actors, and their TTPs (Tactics, Techniques, and Procedures) so they can realistically emulate real-world attacks against their own organization.

  • A is wrong because intelligence about attacks targeting specific software/OS is more relevant to a Blue Team or patch management function - it's defensive awareness, not offensive simulation fuel.
  • C is wrong (incomplete) - while attack analysis on similar organizations can be useful to Red Teams, this option is truncated and describes threat intelligence that broadly serves incident response and Blue Team functions.
  • D is wrong because intelligence about strategic business decision risks is strategic-level intelligence consumed by executives and risk managers, not Red Team operators.

Memory tip: Think "Red Team = Red Threat Actor." A Red Team pretends to be a threat actor, so they need exactly what a real attacker would know - who the active threat actors are, what vulnerabilities exist, and how attacks are carried out (TTPs). If the intelligence sounds defensive or executive-level, it's not for the Red Team.

Topics

#Red Team intelligence needs#Threat intelligence types#TTPs#Vulnerability intelligence

Community Discussion

No community discussion yet for this question.

Full 312-85 Practice