QuestionQ44

Requirements, Planning, Direction, and Review

Highlander, Inc. has decided to integrate threat intelligence into its incident-response process to rapidly detect and recover from various security incidents.

During which incident-response-management phase does the organization use operational and tactical threat intelligence to add context to alerts generated by various security mechanisms?

  • A Phase 2: event
  • B Phase 1: preplanning
  • C Phase 3: incident
  • D Phase 4: breach
Explanation

Operational and tactical threat intelligence enriches security alerts with context such as malicious indicators, adversary activity, and severity, enabling analysts to triage an event and determine whether it should be escalated into an incident. This activity belongs to the event phase. Microsoft documents that integrated threat intelligence enriches alerts with indicators of compromise and threat context.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!