Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsMedium

A SOC analyst receives an alert from the SIEM indicating multiple failed login attempts followed immediately by a successful login to a critical administrative account from an unusual geographic location. The analyst needs to quickly understand the immediate threat and potential impact. Which type of threat intelligence would be most directly useful for immediate decision-making in this scenario?

  1. ATactical Threat Intelligence
  2. BOperational Threat Intelligence
  3. CStrategic Threat Intelligence
  4. DTechnical Threat Intelligence
Show answer & explanation

Correct answer: D. Technical Threat Intelligence

Technical threat intelligence provides specific, actionable data like IP addresses, hashes, and indicators of compromise (IOCs) that are immediately useful for blocking or detecting malicious activity at a technical level during an active incident.

Why the other options are wrong

  • A. Tactical threat intelligence focuses on TTPs (Tactics, Techniques, and Procedures) of threat actors, which is useful for defenders but less immediate than technical IOCs.
  • B. Operational threat intelligence provides context on specific attacks or campaigns, which is helpful but less granular and immediately actionable than technical indicators for blocking.
  • C. Strategic threat intelligence is high-level, long-term, and focuses on adversary capabilities and intentions, not immediate incident response.

Technical Threat Intelligence

Specific, low-level data points (Indicators of Compromise - IOCs) that can be used directly in security tools for detection and prevention.

  • Includes IP addresses, domains, file hashes, URLs.
  • Most actionable for immediate defense.
  • Often consumed by SIEMs, firewalls, EDRs.

Memory trick: STOP making bad choices with your intelligence!

More Security Operations questions