ExamRange

CSA (312-39) SOC Simulation Lab

In this scenario, you will step out of the daily SIEM alerts and review a Cyber Threat Intelligence (CTI) program charter. You will learn to identify strategic components required to make threat intelligence actionable across an organization.

Scenario Context

You are a Senior Threat Intelligence Analyst reviewing a draft CTI strategy document proposed by Shawn, the newly hired Security Manager at Lee Inc. Solutions. The organization currently ingests STIX/TAXII feeds into their SIEM (Sentinel), but the SOC is suffering from alert fatigue, and the CISO isn't seeing a return on investment (ROI) from the TI subscriptions.

Shawn's draft outlines excellent technical components, but as a senior analyst, you know that technical capability alone won't integrate CTI into the business.

Security Environment (Program Assessment)

Review the following extract from the internal SOC Maturity Assessment:

[ASSESSMENT_ID: MAT-CTI-042] Category: Threat Intelligence Integration -------------------------------------------------- Observation 1: Indicator of Compromise (IoC) ingestion is fully automated. Observation 2: Threat analysts generate weekly APT capability reports. Observation 3: Executive leadership and IT Operations do not consume or action these reports. Observation 4: Budget for a dedicated Threat Intel Platform (TIP) was recently denied. Conclusion: The program suffers from a lack of stakeholder alignment and program justification.

Question

Shawn is a security manager working at Lee Inc Solution. His organization wants to develop threat intelligent strategy plan. As a part of threat intelligent strategy plan, he suggested various components, such as threat intelligence requirement analysis, intelligence and collection planning, asset identification, threat reports, and intelligence buy-in.

Which one of the following components he should include in the above threat intelligent strategy plan to make it effective?

SOC Hint: Look at Observations 3 and 4 in the telemetry. The program is failing because nobody is supporting or funding it. What strategic component addresses stakeholder support?

Expert Insight

What is happening:
Lee Inc. Solutions is building a CTI program but is facing a common strategic failure: they are producing intelligence that no one is using, and they are losing budget. To make a Threat Intelligence strategy effective, it cannot just be a technical exercise; it requires explicit alignment with business goals to secure support from stakeholders (the C-Suite, IT Ops, and SOC management).

Why Threat buy-in (C) is correct:
"Threat buy-in" (or Intelligence buy-in) is the process of securing stakeholder sponsorship. Without buy-in, you won't get the budget for tools (like a TIP), and your intelligence reports will be ignored by the teams responsible for patching vulnerabilities or updating firewall rules. It is a foundational *strategic* component.

Why the others are wrong:

MINI LESSON: The CTI Lifecycle & Stakeholder Alignment

As a senior analyst, you must understand that threat intelligence operates on a continuous lifecycle. The very first step dictates the success of the entire program:

  • 1. Direction & Planning: This is where Buy-in occurs. You must interview stakeholders (CISO, Fraud Team, SOC L1s) to understand their Priority Intelligence Requirements (PIRs). If you don't ask what they need, they won't use what you build.
  • 2. Collection: Gathering raw data (OSINT, commercial feeds, internal SIEM logs).
  • 3. Processing: Normalizing data (e.g., converting STIX 1.0 to STIX 2.1).
  • 4. Analysis: Adding context to raw data so it becomes true intelligence.
  • 5. Dissemination: Delivering the intelligence in the right format (YARA rules for SOC, executive summaries for the Board).
  • 6. Feedback: Going back to stakeholders to ask if the intelligence was useful, closing the loop on buy-in.