QuestionQ84

Data Collection and Processing

Marie, a threat analyst at an organization called TechSavvy, was asked to conduct operational threat intelligence analysis to obtain contextual information about security events and incidents.

Which of the following sources must Marie use to conduct operational threat intelligence analysis?

  • A Attack group reports, attack campaign reports, incident reports, malware samples
  • B Activity-related attacks, social media sources, chat room conversations
  • C OSINT, security industry white papers, human contacts
  • D Malware indicators, network indicators, e-mail indicators
Explanation

Operational threat intelligence contextualizes security events and incidents through detailed information about attack groups, attack campaigns, incidents, and malware. Attack group and campaign reports identify adversary activity and intent, while incident reports and malware samples provide event-specific technical and operational context.

Community Discussion

No comments yet. Be the first to start the discussion!