nerdexam
EC-Council

312-85 · Question #35

Jian is a member of the security team at Trinity, Inc. He was conducting a real-time assessment of system activities in order to acquire threat intelligence feeds. He acquired feeds from sources…

The correct answer is A. Internal intelligence feeds. Option A is correct because honeynets, P2P monitoring, infrastructure logs, and application logs are all sources that originate within the organization's own environment - making them internal intelligence feeds that Jian's team controls and generates directly. External…

Threat Intelligence Feeds and Sources

Question

Jian is a member of the security team at Trinity, Inc. He was conducting a real-time assessment of system activities in order to acquire threat intelligence feeds. He acquired feeds from sources like honeynets, P2P monitoring. infrastructure, and application logs. Which of the following categories of threat intelligence feed was acquired by Jian?

Options

  • AInternal intelligence feeds
  • BExternal intelligence feeds
  • CCSV data feeds
  • DProactive surveillance feeds

How the community answered

(35 responses)
  • A
    89% (31)
  • B
    3% (1)
  • C
    3% (1)
  • D
    6% (2)

Explanation

Option A is correct because honeynets, P2P monitoring, infrastructure logs, and application logs are all sources that originate within the organization's own environment - making them internal intelligence feeds that Jian's team controls and generates directly. External intelligence feeds (B) come from outside the organization, such as third-party threat intelligence vendors, ISACs, or open-source threat intel providers - none of which Jian is using here. CSV data feeds (C) describe a delivery format for threat indicators, not a source category, so it's a category error. Proactive surveillance feeds (D) is not a recognized standard category in threat intelligence taxonomy and is a distractor designed to sound plausible.

Memory tip: Think "internal = in-house." If the data comes from systems your org owns and operates (logs, honeypots, network monitors), it's internal. If it comes from a vendor or outside community, it's external.

Topics

#Internal intelligence feeds#Threat intelligence sources#Honeynets#System monitoring

Community Discussion

No community discussion yet for this question.

Full 312-85 Practice