CompTIA Security+ (SY0-701)Security OperationsMedium

A security analyst is reviewing a SIEM dashboard and notices a significant increase in outbound DNS queries to domains known to be associated with a recent malware campaign described in a public threat intelligence report. This type of information is most useful for which aspect of security operations?

  1. ATactical threat intelligence
  2. BOperational threat intelligence
  3. CStrategic threat intelligence
  4. DTechnical threat intelligence
Show answer & explanation

Correct answer: B. Operational threat intelligence

Operational threat intelligence provides context about specific attacks, campaigns, and adversary motivations and tactics. Recognizing an increase in activity related to a known malware campaign (as described in a public report) falls under operational intelligence, helping the analyst understand *how* the threat operates and *who* might be behind it.

Why the other options are wrong

  • A. Tactical threat intelligence focuses on adversary TTPs (Tactics, Techniques, and Procedures), but operational intelligence provides the broader context of specific campaigns.
  • C. Strategic threat intelligence focuses on high-level adversary capabilities and long-term trends, not specific campaign details.
  • D. Technical threat intelligence deals with specific IOCs like malicious domains and IP addresses; while the analyst is using these, the *context* of a 'recent malware campaign' makes it operational.

Operational Threat Intelligence

Threat intelligence that provides context and details about specific ongoing or recent attacks, campaigns, and adversary intent, helping defenders understand 'who, what, and how' of a threat.

  • Focuses on specific campaigns and their characteristics.
  • Helps understand adversary motivations and TTPs in context.
  • Often derived from public reports, dark web monitoring, and incident response.

Memory trick: Operational: 'Ops' means understanding the whole operation.

More Security Operations questions