Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsMedium
A SOC team is evaluating various threat intelligence feeds to enhance their defensive capabilities. They are particularly interested in a feed that provides highly specific, actionable information about current attacks targeting their industry, including indicators of compromise (IOCs) that can be directly integrated into their security tools. Which type of threat intelligence is being prioritized?
- AStrategic Threat Intelligence
- BTactical Threat Intelligence
- CTechnical Threat Intelligence
- DOperational Threat Intelligence
Show answer & explanationAnswer & explanation
Correct answer: C. Technical Threat Intelligence
Technical Threat Intelligence focuses on specific, immediate, and actionable indicators of compromise (IOCs) such as IP addresses, hashes, and domain names that can be directly used in security tools like SIEMs, firewalls, and EDRs for detection and blocking. The scenario emphasizes 'highly specific, actionable information' and 'IOCs that can be directly integrated'.
Why the other options are wrong
- A. Strategic intelligence is high-level, long-term, and non-technical, providing insights into adversary motivations and capabilities.
- B. Tactical intelligence is often used interchangeably with Technical intelligence, but Technical specifically emphasizes the machine-readable IOCs for direct integration.
- D. Operational intelligence focuses on attacker TTPs (Tactics, Techniques, and Procedures) and campaign details, often more narrative than direct IOCs.
Technical Threat Intelligence
Detailed, machine-readable information about specific Indicators of Compromise (IOCs) used by attackers.
- Includes IP addresses, domain names, file hashes, and URLs.
- Directly actionable for security tools (SIEM, firewall, EDR).
- Focuses on immediate detection and prevention.
Memory trick: Think of intelligence like a telescope (strategic) to a microscope (technical).