QuestionQ55
Proactive Threat DetectionA security analyst on a multinational corporation's Threat Intelligence team must improve the organization's ability to detect stealthy malware infections. During an investigation, the analyst notices an unusually high number of DNS requests to domains matching patterns commonly linked to Domain Generation Algorithms (DGAs). Recognizing that these automated domain requests may indicate malware attempting to communicate with its Command & Control (C2) infrastructure, the analyst determines that current detection capabilities may be insufficient.
To counter these threats effectively, the security team must define intelligence requirements, including identifying critical data sources, refining detection criteria, and improving threat-monitoring strategies. Which stage of the Cyber Threat Intelligence (CTI) process does this scenario correspond to?
- A Requirement Analysis
- B Filtering CTI
- C Intelligence Buy-In
- D Automated tool
Community Discussion