CSA (312-39) SOC Simulation Lab
Scenario Context
You are managing the Threat Intelligence Platform (TIP) at GlobalFinance Corp. Your team ingests thousands of data points daily. Some go directly to the SIEM as blocklists, some go to the Threat Hunting team as YARA rules, and some go to the CISO for the quarterly board meeting.
You are reviewing a newly published executive brief to ensure it goes to the correct internal stakeholder. The brief does not contain IP addresses or file hashes; instead, it outlines a shift in the geopolitical landscape affecting the financial sector.
Security Environment (TIP Extract)
Review the following extract from your Threat Intelligence Platform's report repository:
Question
The threat intelligence, which will help you, understand adversary intent and make informed decision to ensure appropriate security in alignment with risk.
What kind of threat intelligence described above?
Expert Insight
What is happening:
The SOC is processing a high-level report that details the who and why of an attack trend. This document is devoid of technical artifacts (like IPs or domains). Instead, it discusses adversary intent, geopolitical shifts, and business risk. The goal is to inform executive leadership so they can make risk-based decisions, such as increasing the budget for DLP solutions.
Why Strategic Threat Intelligence (B) is correct:
Strategic Threat Intelligence provides high-level information regarding the cybersecurity posture, threats, financial impacts, and trends. It specifically focuses on adversary intent and broad capabilities, allowing executives (CISO, Board of Directors) to align security spending and strategy with actual business risk.
Why the others are wrong:
- Tactical Threat Intelligence (A): Focuses on specific Indicators of Compromise (IoCs) such as IP addresses, malicious domains, and file hashes. It is used by L1/L2 SOC analysts or automated via SIEM/Firewalls for immediate blocking.
- Operational Threat Intelligence (D): Focuses on the "How" and "Where" (TTPs - Tactics, Techniques, and Procedures). It is used by Threat Hunters and Detection Engineers to build SIEM correlation rules based on MITRE ATT&CK framework behaviors.
- Functional Threat Intelligence (C): This is a distractor term. It is not a recognized category in standard CTI frameworks.
MINI LESSON: The Threat Intelligence Pyramid
To succeed in a SOC, you must route the right intelligence to the right consumer. Memorize this hierarchy:
- Strategic (High-Level): Who and Why. Focuses on trends, intent, and risk. Consumed by the C-Suite/Board to drive strategy and budget. Format: Whitepapers, executive briefs.
- Operational (Mid-Level): How and Where. Focuses on adversary behavior (TTPs), campaign tracking, and malware families. Consumed by Threat Hunters, IR teams, and SOC L3. Format: MITRE ATT&CK mappings, YARA rules.
- Tactical / Technical (Low-Level): What. Focuses on immediate, ephemeral artifacts (IoCs like IPs, hashes, URLs). Consumed by SOC L1s, SIEMs, Firewalls, and EDRs. Format: STIX/TAXII feeds, CSV lists.