Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsHard
A cybersecurity team is evaluating different threat intelligence feeds. They are particularly interested in a feed that provides real-time information on newly discovered zero-day vulnerabilities, active exploit kits, and indicators of compromise (IoCs) related to emerging malware campaigns. Which characteristic best describes this type of threat intelligence?
- AStrategic Threat Intelligence
- BOperational Threat Intelligence
- CTechnical Threat Intelligence
- DTactical Threat Intelligence
Show answer & explanationAnswer & explanation
Correct answer: C. Technical Threat Intelligence
Technical threat intelligence focuses on specific, actionable data like IoCs (IP addresses, domains, file hashes), zero-day vulnerabilities, and exploit details. This type of intelligence is directly consumable by security tools and analysts for immediate detection and prevention, fitting the scenario's focus on real-time, emerging threats.
Why the other options are wrong
- A. Strategic threat intelligence provides high-level insights for executive decision-making, focusing on long-term trends and geopolitical factors, not real-time IoCs.
- B. Operational threat intelligence focuses on specific attack campaigns and actor motivations, often providing context for active threats, but the direct mention of 'zero-day vulnerabilities, active exploit kits, and IoCs' leans more towards the granular details of technical intelligence.
- D. Tactical threat intelligence focuses on attacker TTPs (Tactics, Techniques, and Procedures), helping security teams understand how attacks are carried out, rather than specific IoCs or zero-days.
Types of Threat Intelligence
Categorization of threat intelligence based on its audience, purpose, and level of detail.
- Strategic: High-level, long-term trends, executive-focused.
- Tactical: Attacker TTPs, security team-focused.
- Operational: Specific campaigns, actor motivations, incident response-focused.
- Technical: IoCs, vulnerability details, machine-consumable, real-time detection-focused.
Memory trick: Threat intel has levels: Strategic for leaders, Tactical for methods, Operational for campaigns, Technical for direct actions.