CSA (312-39) SOC Simulation Lab
Master the classification of Threat Intelligence types. In this scenario, you'll evaluate an analyst's OSINT and HUMINT collection efforts to determine the correct intelligence tier.
Scenario Context
GreenTech Solutions has noticed an uptick in perimeter scanning against their public-facing API gateways. John, a dedicated Threat Intelligence Analyst on the team, is tasked with identifying the actor behind this activity before a major incident occurs.
Instead of relying purely on SIEM logs, John shifts his focus externally. He monitors specific hacktivist Telegram channels, scrapes chatter from deep web forums (using dummy accounts), and analyzes social media trends regarding GreenTech's upcoming controversial product launch.
Security Environment
Analyst: John (Threat Intel)
Current Task: Compiling an intelligence briefing for the Incident Response Lead.
--------------------------------------------------
SOURCE: Telegram Channel (ID: xxxx_OpGreen)
CONTENT: "Targeting greentech.local on Friday. Let's bring their APIs down."
--------------------------------------------------
SOURCE: Dark Web Forum (Exploit[.]in - Initial Access Brokers)
CONTENT: User 'b4db0y' posting: "Selling active VPN credentials for GreenTech. 0.5 BTC."
--------------------------------------------------
ASSESSMENT: Imminent threat of DDoS against API infrastructure coupled with potential unauthorized VPN access attempts by affiliated actors. Recommend immediate enforcement of Geo-blocking and MFA audit.
--------------------------------------------------
_
This data provides the "Who", "Why", and "When" of an impending attack, directly informing immediate defensive postures.
Question
John, a threat analyst at GreenTech Solutions, wants to gather information about specific threats against the organization. He started collecting information from various sources, such as humans, social media, chat room, and so on, and created a report that contains malicious activity.
Which of the following types of threat intelligence did he use?
Expert Insight: Senior SOC Analyst Mentorship
What is happening:
John is stepping outside the traditional SIEM console to proactively hunt for adversary intent. By monitoring dark web forums (HUMINT/Deep Web) and social media (OSINT), he is gathering context about a specific, impending attack campaign. He isn't just looking at what the malware does; he's looking at who is deploying it and why.
Why D is correct:
Operational Threat Intelligence answers the "Who, What, and Why" of specific impending attacks. It relies heavily on gathering intel from human interactions, chat rooms, social media, and threat actor infrastructure tracking. It provides actionable context for SOC managers and Incident Responders to prioritize defenses for specific campaigns.
Why the others are wrong:
- Strategic (A): Consumed by the C-Suite and Board. It deals with long-term trends, financial impact, and high-level risk (e.g., "Ransomware costs in the energy sector are up 40%").
- Tactical (C): Consumed by SOC analysts and architects. Focuses on attacker methodologies, tools, techniques, and procedures (TTPs), often mapped to the MITRE ATT&CK framework.
- Technical (B): Consumed by automated systems (SIEMs, EDRs, Firewalls). This is the lowest level of intel, consisting of raw Indicators of Compromise (IOCs) like malicious IP addresses, file hashes, and domains.
SOC Mini-Lesson: The Threat Intel Consumption Matrix
To succeed in a SOC, you must understand your audience. You don't hand an IP blocklist to the CEO, and you don't hand a 30-page geopolitical report to a firewall administrator.
- Strategic: Target = CISO/Executives. Focus = Budgeting & Risk.
- Operational: Target = SOC Managers/IR Leads. Focus = Campaign tracking & immediate posture adjustment (John's report).
- Tactical: Target = Tier 2/3 Analysts. Focus = Detection engineering (writing YARA/Splunk rules for TTPs).
- Technical: Target = Automated API feeds (STIX/TAXII). Focus = Blocking raw IOCs.
Ready to validate your skills further?
Explore more CSA simulations by ExamRange →