CSA (312-39) SOC Simulation Lab

Master Cyber Threat Intelligence (CTI) classifications. Learn how to map different types of intelligence to their intended audience, from SIEM parsers to the Board of Directors.

Scenario Context

You are a Senior Threat Analyst at Apex Global Bank. The CISO has requested a brief for the Board of Directors concerning the security budget for the upcoming fiscal year. The Board is non-technical; they do not care about MD5 hashes or specific zero-day vulnerabilities. They want to know who is targeting the financial sector, why, and the potential financial impact of a successful breach.

To build your threat model and justify the budget for a new anti-fraud platform, you must aggregate intelligence that speaks to these high-level business risks.

Security Environment

You log into your CTI Platform (e.g., Recorded Future / MISP). Notice the difference between the data feeds available to you.

[CTI FEED EXTRACT: Board-Level Threat Briefing]
INTEL_CLASSIFICATION: ***REDACTED*** REPORT_ID: TR-2023-11-FIN SUBJECT: APT38 (Lazarus Group) shift toward SWIFT infrastructure in APAC EXECUTIVE SUMMARY: Due to recent international economic sanctions, state-sponsored actors aligned with North Korea are increasingly targeting tier-1 financial institutions to generate state revenue. Their primary objective has shifted from traditional ransomware to fraudulent SWIFT transactions. RISK ASSESSMENT: High likelihood of attack in Q3/Q4. Potential financial impact exceeds $50M per incident. RECOMMENDATION: Allocate Q1 budget to enhance SWIFT enclave monitoring and anomaly detection.

Question

You are a SOC analyst working for a leading financial institution, and you have been assigned the task of developing a comprehensive threat model to safeguard the organization's critical assets. Senior management is particularly concerned about the potential financial and reputational damage that could result from a breach. To address these concerns, you must focus on intelligence that provides insights into high-level risks, geopolitical threats, and emerging cybercriminal strategies that could have long-term implications for your organization's security posture.

Which type of threat intelligence are you seeking to obtain?

SOC Hint: Look at the audience: Senior management. Look at the content: High-level risks, geopolitical threats, financial impact. This isn't about *how* to detect the attack, it's about *why* the attack matters to the business.

Expert Insight

1. What is happening

As a senior analyst, you are stepping out of the SIEM and into the boardroom. You are taking raw data (like an uptick in phishing against bank tellers) and translating it into business risk (e.g., "State-sponsored actors are trying to breach our SWIFT system to evade international sanctions"). This helps executives make informed decisions about where to spend security budget.


2. Why the correct answer is correct (B)

Strategic Threat Intelligence is designed specifically for executive leadership (C-Suite, Board of Directors). It focuses on the "Who" and the "Why" of cyber threats. It covers high-level trends, geopolitical motivations, attacker attribution, and the potential financial or reputational impact on the organization. It is non-technical and used to guide long-term cybersecurity strategy and investments.


3. Why the other options are wrong


4. Real-world SOC application

Junior analysts often make the mistake of presenting Technical or Tactical intelligence to leadership. If you tell a CEO "We blocked 500 connections to a known Cobalt Strike C2 server," they won't know what that means, or worse, they'll just assume the firewall is doing its job and deny your budget request. Instead, a Senior Analyst uses Strategic Intelligence: "A known ransomware cartel is actively targeting our sector. We contained early reconnaissance, but to mitigate a potential $10M ransom event, we need to fund an MDR service for off-hours coverage."


MINI LESSON: The 4 Levels of CTI

To master the CSA exam, memorize the audience and purpose for each level:

  • Strategic: For Executives. Focus: Risk, Trends, Motivation.
  • Operational: For SOC/IR Management. Focus: Impending campaigns, Threat Actor tracking.
  • Tactical: For SOC Analysts/Hunters. Focus: TTPs (MITRE ATT&CK), Detection Engineering.
  • Technical: For Security Tools (SIEM/FW). Focus: IOCs (Hashes, IPs, Domains).

Improve your threat detection and IR planning skills with more hands-on scenarios.

Explore more CSA simulations