Welcome to this ExamRange CSA simulation. As a SOC Operations Manager, you are reviewing a new Threat Intelligence Platform (TIP) feed. You must correctly classify this intelligence to ensure it routes to the right team for SIEM rule tuning and EDR deployment.
Organization: OmniTrust Bank
Current Status: Threat Intel Processing
Your Threat Intelligence Platform (TIP) just digested a STIX 2.1 report regarding a new financial threat actor, tracked as "GoldDigger".
The report details exactly how this group breaches perimeters using HTML smuggling, drops heavily obfuscated PowerShell payloads, and subsequently utilizes Cobalt Strike for lateral movement. Your SOC analysts and Threat Hunters need to ingest this data immediately to map these behaviors against your current SIEM coverage.
Before assigning the tuning tasks, you must categorize this intelligence type appropriately within your SOC workflow documentation.
TIP Alert | Source: ISAC Financial Feed | Format: JSON/STIX
Which of the following threat intelligence helps cyber security professionals such as security operations managers, network operations center and incident responders to understand how the adversaries are expected to perform the attack on the organization, and the technical capabilities and goals of the attackers along with the attack vectors?
We are parsing a threat intelligence report detailing the specific behaviors (TTPs) of an adversary. As SOC analysts, we use this information to map out the attacker's path—like looking at a playbook. If we know the actor uses HTML smuggling (T1027.006), we can proactively tune our email gateways and web proxies to look for anomalous blob downloads, shifting from reactive alerting to proactive defense.
Tactical Threat Intelligence focuses exactly on the "how"—the attacker's Tactics, Techniques, and Procedures (TTPs), tools, and attack vectors. This is the primary intelligence tier consumed by SOC Analysts, Threat Hunters, and Incident Responders to develop robust, behavioral-based detection rules (like Splunk SPL queries or CrowdStrike IOAs).
A. Analytical Threat Intelligence: This is a distractor. While analysis is a phase of the intelligence lifecycle, it is not one of the four standard EC-Council TI classifications (Strategic, Operational, Tactical, Technical).
B. Operational Threat Intelligence: This focuses on the context of a specific incoming attack or active campaign (the "who", "where", and "when"). It provides early warning of impending threats, not general capability mapping.
C. Strategic Threat Intelligence: This is high-level, non-technical reporting aimed at the C-suite and Board of Directors. It discusses business risks, financial implications, and overarching global threat trends, not specific attack vectors.
When dealing with threat intelligence, remember David Bianco’s "Pyramid of Pain."
At the bottom, you have Technical TI (hashes, IP addresses, domains). These are easy for attackers to change and trivial for us to block. However, Tactical TI sits at the very top of the pyramid (TTPs).
When you build detections based on Tactical TI (e.g., detecting the behavior of PowerShell spawning from a Word document, rather than just blocking a specific malicious Word file hash), you force the adversary to completely reinvent their attack strategy. This is why Tactical TI is the most valuable asset for a SOC.
Ready to tackle more realistic SOC scenarios and prepare for your CSA certification?
Explore More CSA Simulations