CompTIA Security+ (SY0-701)Security OperationsEasy
A security analyst is investigating a suspected data exfiltration event. The analyst discovers that several internal IP addresses are making uncharacteristic outbound connections to a known malicious IP address associated with a botnet command and control server. Which type of threat intelligence is the analyst primarily using to identify this activity?
- AOperational threat intelligence
- BTechnical threat intelligence
- CTactical threat intelligence
- DStrategic threat intelligence
Show answer & explanationAnswer & explanation
Correct answer: B. Technical threat intelligence
Technical threat intelligence focuses on specific, actionable data points like IP addresses, domains, and file hashes that indicate malicious activity. The analyst is using a known malicious IP to identify the activity.
Why the other options are wrong
- A. Operational threat intelligence provides context on specific attacks, campaigns, and adversary motivations, which is broader than a single malicious IP.
- C. Tactical threat intelligence focuses on adversary TTPs (Tactics, Techniques, and Procedures), not specific IP addresses.
- D. Strategic threat intelligence provides high-level overviews of the threat landscape and adversary capabilities, not specific indicators.
Technical Threat Intelligence
Actionable data points, such as IP addresses, domains, and file hashes, used to identify malicious activity.
- Focuses on specific indicators of compromise (IOCs).
- Used for immediate detection and blocking.
- Often integrated into security tools like SIEMs and firewalls.
Memory trick: STOT: Strategic, Tactical, Operational, Technical – each gets more specific.