CSA (312-39) SOC Simulation Lab

Master the classification of Threat Intelligence types. In this scenario, you'll evaluate an analyst's OSINT and HUMINT collection efforts to determine the correct intelligence tier.

Scenario Context

GreenTech Solutions has noticed an uptick in perimeter scanning against their public-facing API gateways. John, a dedicated Threat Intelligence Analyst on the team, is tasked with identifying the actor behind this activity before a major incident occurs.

Instead of relying purely on SIEM logs, John shifts his focus externally. He monitors specific hacktivist Telegram channels, scrapes chatter from deep web forums (using dummy accounts), and analyzes social media trends regarding GreenTech's upcoming controversial product launch.

Security Environment

Analyst: John (Threat Intel)
Current Task: Compiling an intelligence briefing for the Incident Response Lead.

# Excerpt from John's internal Threat Briefing draft:
--------------------------------------------------
SOURCE: Telegram Channel (ID: xxxx_OpGreen)
CONTENT: "Targeting greentech.local on Friday. Let's bring their APIs down."
--------------------------------------------------
SOURCE: Dark Web Forum (Exploit[.]in - Initial Access Brokers)
CONTENT: User 'b4db0y' posting: "Selling active VPN credentials for GreenTech. 0.5 BTC."
--------------------------------------------------
ASSESSMENT: Imminent threat of DDoS against API infrastructure coupled with potential unauthorized VPN access attempts by affiliated actors. Recommend immediate enforcement of Geo-blocking and MFA audit.
--------------------------------------------------
_

This data provides the "Who", "Why", and "When" of an impending attack, directly informing immediate defensive postures.

Question

John, a threat analyst at GreenTech Solutions, wants to gather information about specific threats against the organization. He started collecting information from various sources, such as humans, social media, chat room, and so on, and created a report that contains malicious activity.

Which of the following types of threat intelligence did he use?

SOC Hint: Think about the scope and source. It's not high-level financial risk (Strategic), it's not MITRE ATT&CK TTPs (Tactical), and it's not just a raw list of IP addresses (Technical). It's specific intelligence about actor intent gathered from OSINT/HUMINT.

Expert Insight: Senior SOC Analyst Mentorship

What is happening:
John is stepping outside the traditional SIEM console to proactively hunt for adversary intent. By monitoring dark web forums (HUMINT/Deep Web) and social media (OSINT), he is gathering context about a specific, impending attack campaign. He isn't just looking at what the malware does; he's looking at who is deploying it and why.

Why D is correct:
Operational Threat Intelligence answers the "Who, What, and Why" of specific impending attacks. It relies heavily on gathering intel from human interactions, chat rooms, social media, and threat actor infrastructure tracking. It provides actionable context for SOC managers and Incident Responders to prioritize defenses for specific campaigns.

Why the others are wrong:

SOC Mini-Lesson: The Threat Intel Consumption Matrix

To succeed in a SOC, you must understand your audience. You don't hand an IP blocklist to the CEO, and you don't hand a 30-page geopolitical report to a firewall administrator.

  • Strategic: Target = CISO/Executives. Focus = Budgeting & Risk.
  • Operational: Target = SOC Managers/IR Leads. Focus = Campaign tracking & immediate posture adjustment (John's report).
  • Tactical: Target = Tier 2/3 Analysts. Focus = Detection engineering (writing YARA/Splunk rules for TTPs).
  • Technical: Target = Automated API feeds (STIX/TAXII). Focus = Blocking raw IOCs.

Ready to validate your skills further?
Explore more CSA simulations by ExamRange →