Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsMedium
A SOC analyst is reviewing a threat intelligence report that details a newly discovered zero-day vulnerability being actively exploited by a state-sponsored group. The report includes specific malware hashes, C2 server IP addresses, and unique strings found in the malware code. What type of threat intelligence does this information primarily represent?
- AStrategic Threat Intelligence
- BTechnical Threat Intelligence
- CTactical Threat Intelligence
- DOperational Threat Intelligence
Show answer & explanationAnswer & explanation
Correct answer: B. Technical Threat Intelligence
Technical threat intelligence focuses on specific, actionable indicators of compromise (IOCs) such as IP addresses, domains, file hashes, and registry keys. This type of intelligence is directly usable by security tools for detection and blocking. The provided details (malware hashes, C2 IPs, unique strings) are classic examples of technical IOCs.
Why the other options are wrong
- A. Strategic intelligence is high-level, focused on long-term trends and business impact.
- C. Tactical intelligence focuses on TTPs (Tactics, Techniques, and Procedures) used by threat actors.
- D. Operational intelligence provides details on specific attack campaigns and actor motivations.
Technical Threat Intelligence
Technical threat intelligence consists of actionable data points (Indicators of Compromise or IOCs) such as IP addresses, domains, file hashes, and specific malware artifacts that can be used directly by security devices for detection and prevention.
- Highly granular and machine-readable.
- Directly usable for security tool configurations.
- Short shelf-life due to rapid changes.
Memory trick: STOT: Strategic, Tactical, Operational, Technical.