CompTIA Security+ (SY0-701)Security OperationsMedium

A security analyst is reviewing a SIEM dashboard and notices a significant increase in outbound DNS queries from several internal workstations to unusual, newly registered domains. This activity occurs shortly after a successful phishing campaign targeting employees. What type of threat intelligence BEST describes the information about these suspicious domains?

  1. AStrategic Intelligence
  2. BOperational Intelligence
  3. CTactical Intelligence
  4. DVulnerability Intelligence
Show answer & explanation

Correct answer: B. Operational Intelligence

Operational intelligence focuses on specific, actionable details about current or impending attacks, such as indicators of compromise (IOCs) like suspicious domain names, IP addresses, or file hashes. This type of intelligence is directly useful for detection and immediate defense.

Why the other options are wrong

  • A. Strategic intelligence provides high-level insights into an adversary's capabilities, intent, and overall threat landscape, useful for long-term planning.
  • C. Tactical intelligence describes adversary TTPs (Tactics, Techniques, and Procedures), helping defenders understand how attacks are carried out, but not the specific IOCs.
  • D. Vulnerability intelligence focuses on known weaknesses in systems, not active attack indicators.

Operational Threat Intelligence

Actionable threat intelligence that provides specific, technical details (e.g., IOCs) about ongoing or imminent attacks, helping security teams detect and respond immediately.

  • Focuses on specific attack details
  • Includes IOCs like malicious IPs, domains, hashes
  • Useful for immediate detection and response

Memory trick: Strategic is big picture, Tactical is TTPs, Operational is IOCs.

More Security Operations questions