CompTIA Security+ (SY0-701)Security OperationsMedium
A security analyst is reviewing a SIEM dashboard and notices a significant increase in outbound connections from internal workstations to IP addresses in a known hostile nation-state. This trend was identified by correlating internal log data with external threat intelligence feeds. Which type of threat intelligence is being utilized in this scenario?
- ATactical threat intelligence
- BOperational threat intelligence
- CTechnical threat intelligence
- DStrategic threat intelligence
Show answer & explanationAnswer & explanation
Correct answer: B. Operational threat intelligence
Operational threat intelligence provides information about specific attacks, campaigns, and TTPs (Tactics, Techniques, and Procedures) of threat actors. Knowing that certain IP addresses are associated with a hostile nation-state and observing active connections to them is directly actionable intelligence for security operations, making it operational.
Why the other options are wrong
- A. Tactical threat intelligence focuses on TTPs of threat actors, which is related but operational intelligence is more about active threats.
- C. Technical threat intelligence focuses on specific IOCs like IP addresses or hashes, which are components, but the correlation and context make it operational.
- D. Strategic threat intelligence provides high-level insights for executive decision-making, not specific network activity.
Operational Threat Intelligence
Threat intelligence that provides information about specific threats, campaigns, and the TTPs of threat actors, directly aiding security operations.
- Focuses on current, active threats and threat actor methods.
- Helps security teams understand 'how' and 'who' is attacking.
- Directly supports detection, analysis, and response activities.
Memory trick: Operational TI is 'On the Ground' intel for active defense.