nerdexam
EC-Council

312-85 · Question #8

Tracy works as a CISO in a large multinational company. She consumes threat intelligence to understand the changing trends of cyber security. She requires intelligence to understand the current…

The correct answer is B. Strategic users. Option B is correct because Tracy is a CISO - a C-suite executive - who uses threat intelligence at a business level: informing budget decisions, evaluating new technologies, managing risk, and shaping organizational strategy. This is the hallmark of a strategic consumer, who…

Introduction to Threat Intelligence

Question

Tracy works as a CISO in a large multinational company. She consumes threat intelligence to understand the changing trends of cyber security. She requires intelligence to understand the current business trends and make appropriate decisions regarding new technologies, security budget, improvement of processes, and staff. The intelligence helps her in minimizing business risks and protecting the new technology and business initiatives. Identify the type of threat intelligence consumer is Tracy.

Options

  • ATactical users
  • BStrategic users
  • COperational users
  • DTechnical users

How the community answered

(61 responses)
  • A
    3% (2)
  • B
    89% (54)
  • C
    7% (4)
  • D
    2% (1)

Explanation

Option B is correct because Tracy is a CISO - a C-suite executive - who uses threat intelligence at a business level: informing budget decisions, evaluating new technologies, managing risk, and shaping organizational strategy. This is the hallmark of a strategic consumer, who needs high-level, non-technical intelligence about trends and business impact rather than attack specifics.

Why the distractors are wrong:

  • A. Tactical users focus on adversary Tactics, Techniques, and Procedures (TTPs) to improve defensive controls - think security managers and red/blue team leads, not executives making budget calls.
  • C. Operational users are concerned with specific, active or imminent threats and campaigns - typically SOC analysts and incident responders tracking a particular threat actor or attack.
  • D. Technical users consume raw technical indicators (IPs, file hashes, malware signatures) to configure tools and hunt threats - the most granular level, suited for analysts and engineers.

Memory tip: Map the levels to organizational altitude - Technical (ground floor: raw IOCs) → Operational (mid-floor: live campaigns) → Tactical (upper-floor: attacker methods) → Strategic (C-suite penthouse: business risk and investment decisions). Tracy sits at the top.

Topics

#Threat Intelligence Consumer Types#Strategic Threat Intelligence#Executive Decision-Making#CISO Role

Community Discussion

No community discussion yet for this question.

Full 312-85 Practice