312-85 · Question #8
Tracy works as a CISO in a large multinational company. She consumes threat intelligence to understand the changing trends of cyber security. She requires intelligence to understand the current…
The correct answer is B. Strategic users. Option B is correct because Tracy is a CISO - a C-suite executive - who uses threat intelligence at a business level: informing budget decisions, evaluating new technologies, managing risk, and shaping organizational strategy. This is the hallmark of a strategic consumer, who…
Question
Tracy works as a CISO in a large multinational company. She consumes threat intelligence to understand the changing trends of cyber security. She requires intelligence to understand the current business trends and make appropriate decisions regarding new technologies, security budget, improvement of processes, and staff. The intelligence helps her in minimizing business risks and protecting the new technology and business initiatives. Identify the type of threat intelligence consumer is Tracy.
Options
- ATactical users
- BStrategic users
- COperational users
- DTechnical users
How the community answered
(61 responses)- A3% (2)
- B89% (54)
- C7% (4)
- D2% (1)
Explanation
Option B is correct because Tracy is a CISO - a C-suite executive - who uses threat intelligence at a business level: informing budget decisions, evaluating new technologies, managing risk, and shaping organizational strategy. This is the hallmark of a strategic consumer, who needs high-level, non-technical intelligence about trends and business impact rather than attack specifics.
Why the distractors are wrong:
- A. Tactical users focus on adversary Tactics, Techniques, and Procedures (TTPs) to improve defensive controls - think security managers and red/blue team leads, not executives making budget calls.
- C. Operational users are concerned with specific, active or imminent threats and campaigns - typically SOC analysts and incident responders tracking a particular threat actor or attack.
- D. Technical users consume raw technical indicators (IPs, file hashes, malware signatures) to configure tools and hunt threats - the most granular level, suited for analysts and engineers.
Memory tip: Map the levels to organizational altitude - Technical (ground floor: raw IOCs) → Operational (mid-floor: live campaigns) → Tactical (upper-floor: attacker methods) → Strategic (C-suite penthouse: business risk and investment decisions). Tracy sits at the top.
Topics
Community Discussion
No community discussion yet for this question.