CompTIA Security+ (SY0-701)Security OperationsMedium

A security analyst is reviewing a SIEM dashboard and notices a significant increase in outbound connections from internal workstations to IP addresses in a known hostile nation-state. This trend was identified by correlating internal log data with external threat intelligence feeds. Which type of threat intelligence is being utilized in this scenario?

  1. ATactical threat intelligence
  2. BOperational threat intelligence
  3. CTechnical threat intelligence
  4. DStrategic threat intelligence
Show answer & explanation

Correct answer: B. Operational threat intelligence

Operational threat intelligence provides information about specific attacks, campaigns, and TTPs (Tactics, Techniques, and Procedures) of threat actors. Knowing that certain IP addresses are associated with a hostile nation-state and observing active connections to them is directly actionable intelligence for security operations, making it operational.

Why the other options are wrong

  • A. Tactical threat intelligence focuses on TTPs of threat actors, which is related but operational intelligence is more about active threats.
  • C. Technical threat intelligence focuses on specific IOCs like IP addresses or hashes, which are components, but the correlation and context make it operational.
  • D. Strategic threat intelligence provides high-level insights for executive decision-making, not specific network activity.

Operational Threat Intelligence

Threat intelligence that provides information about specific threats, campaigns, and the TTPs of threat actors, directly aiding security operations.

  • Focuses on current, active threats and threat actor methods.
  • Helps security teams understand 'how' and 'who' is attacking.
  • Directly supports detection, analysis, and response activities.

Memory trick: Operational TI is 'On the Ground' intel for active defense.

More Security Operations questions