CompTIA Security+ (SY0-701)Security OperationsMedium
A security analyst is investigating a suspected data exfiltration event. The analyst discovers a specific IP address that was observed making unusually large outbound connections to an external server, followed by a sudden drop in network traffic from the internal host. This IP address was previously unknown to the organization. What type of information does this IP address represent in the context of threat intelligence?
- ATechnical threat intelligence
- BStrategic threat intelligence
- CTactical threat intelligence
- DOperational threat intelligence
Show answer & explanationAnswer & explanation
Correct answer: A. Technical threat intelligence
Technical threat intelligence consists of indicators of compromise (IOCs) such as specific IP addresses, domain names, file hashes, or URLs that can be used to identify and block threats. The scenario describes a specific, actionable piece of data (an IP address) directly linked to malicious activity.
Why the other options are wrong
- B. Strategic threat intelligence provides high-level insights into attacker motivations, capabilities, and trends, not specific IOCs.
- C. Tactical threat intelligence describes attacker TTPs (Tactics, Techniques, Procedures), which are more abstract than a specific IP address.
- D. Operational threat intelligence focuses on specific upcoming attacks or campaigns, often involving human intelligence, more detailed than a single IP.
Technical Threat Intelligence
Actionable, low-level data points (Indicators of Compromise - IOCs) that can be used to detect and block specific threats, such as malicious IP addresses, domain names, file hashes, or URLs.
- Focuses on specific IOCs.
- Easily integrated into security tools (firewalls, SIEM).
- Often short-lived as attackers change infrastructure.
Memory trick: For 'Technical' details like an IP, think 'T' for 'Tiny' factual pieces.