Cisco CCNP Security Core (SCOR) 350-701Security ConceptsEasy
A security operations center (SOC) receives a report from a third-party vendor detailing newly discovered vulnerabilities in a widely used software library, along with potential exploit techniques and indicators of compromise (IoCs). The SOC team uses this information to update their detection rules and patch management priorities. Which security concept does this scenario primarily illustrate?
- ASecurity metrics
- BSecurity awareness training
- CThreat intelligence
- DSecurity reporting
Show answer & explanationAnswer & explanation
Correct answer: C. Threat intelligence
Threat intelligence involves collecting, processing, and analyzing information about potential or current threats to an organization, then using this to make informed security decisions, as described in the scenario.
Why the other options are wrong
- A. Security metrics are measurements of security effectiveness, not raw threat data.
- B. Security awareness training educates users, not about specific threat data for SOC operations.
- D. Security reporting is about communicating security status, not the input data for threat detection.
Threat Intelligence
Evidence-based knowledge, including context, mechanisms, indicators, implications, and actionable advice about an existing or emerging menace or hazard to assets.
- Provides context for security events and helps predict future attacks.
- Can be strategic, operational, or tactical.
- Used to enhance detection, prevention, and response capabilities.
Memory trick: Intelligence helps SOCs respond to threats proactively.