nerdexam
EC-Council

312-85 · Question #9

An organization suffered many major attacks and lost critical information, such as employee records, and financial information. Therefore, the management decides to hire a threat analyst to extract…

The correct answer is B. OSINT, CTI vendors, ISAO/ISACs. Option B is correct because strategic threat intelligence is high-level, executive-facing intelligence focused on trends, posture, and financial impact - exactly what OSINT (broad publicly available information), CTI vendors (commercial providers who aggregate and analyze…

Threat Intelligence Feeds and Sources

Question

An organization suffered many major attacks and lost critical information, such as employee records, and financial information. Therefore, the management decides to hire a threat analyst to extract the strategic threat intelligence that provides high-level information regarding current cyber-security posture, threats, details on the financial impact of various cyber-activities, and so on. Which of the following sources will help the analyst to collect the required intelligence?

Options

  • AActive campaigns, attacks on other organizations, data feeds from external third parties
  • BOSINT, CTI vendors, ISAO/ISACs
  • CCampaign reports, malware, incident reports, attack group reports, human intelligence
  • DHuman, social media, chat rooms

How the community answered

(33 responses)
  • B
    91% (30)
  • C
    6% (2)
  • D
    3% (1)

Explanation

Option B is correct because strategic threat intelligence is high-level, executive-facing intelligence focused on trends, posture, and financial impact - exactly what OSINT (broad publicly available information), CTI vendors (commercial providers who aggregate and analyze threat landscapes), and ISAOs/ISACs (industry-specific information sharing groups) are designed to deliver.

Option A describes sources for operational intelligence - active campaigns and real-time data feeds are used by security teams responding to ongoing threats, not by management assessing overall posture. Option C (malware samples, incident reports, attack group reports) points to tactical intelligence, which informs specific defensive actions and technical responses rather than executive decision-making. Option D (human sources, social media, chat rooms) represents raw collection methods, more aligned with technical or operational intelligence gathering like tracking threat actor chatter - too granular and unrefined for strategic use.

Memory tip: Think "Strategic = Structured & Aggregated." OSINT, CTI vendors, and ISACs all produce processed, high-level intelligence consumed by decision-makers - contrast this with raw feeds (Option A), technical artifacts (Option C), or unfiltered human sources (Option D), which feed lower-level intelligence tiers.

Topics

#threat intelligence sources#OSINT#CTI vendors#ISAO/ISACs

Community Discussion

No community discussion yet for this question.

Full 312-85 Practice