ExamRange

CSA (312-39) SOC Simulation Lab

Master the Cyber Threat Intelligence (CTI) lifecycle. In this module, you will analyze how a SOC transitions from high-level strategic requirements into actionable intelligence collection planning.

Scenario Context

Organization: Vanguard Financial Group
Phase: CTI Lifecycle - Direction & Planning
Objective: Operationalize Q3 Threat Requirements

The CISO has just finalized the Priority Intelligence Requirements (PIRs) for the quarter. Top concerns include FIN7 fraud campaigns, tailored spear-phishing against executives, and APT38 (Lazarus) targeting SWIFT infrastructure.

As the Threat Intelligence Lead, you cannot simply say "monitor everything." You are now looking at the CTI platform to assign specific tools (e.g., FS-ISAC TAXII feeds, CrowdStrike Falcon X), allocate specific L3 hunter hours, and define exact data sources (e.g., SIEM proxy logs) to answer the CISO's requirements.

Telemetry: CTI Management Platform

ThreatConnect / MISP Allocation Ticket Status: ACTIVE
# CTI ALLOCATION TICKET: TSK-2023-114
Related_PIR: PIR-02 (Nation-State targeting SWIFT)
Target_Adversary: APT38 / Lazarus Group

Assigned_To: Analyst_Hunt_Team_Alpha
Time_Allocation: 12 Hours / Week

Collection_Sources:
  - FS-ISAC TAXII Feed (poll every 4h)
  - Splunk Index: ext_proxy_logs
  - EDR: Custom IOA ruleset deployment

Objective: 
Extract and correlate known APT38 C2 infrastructure from external feeds against internal egress proxy logs to detect beaconing behavior.

Notice how the high-level requirement (PIR-02) is being broken down into specific assignments of personnel, time, and collection tools.

Question

A security operation center team in a large financial institution is working on implementing a threat intelligence strategy to proactively defend against cyber threats. To ensure the success of this initiative, they need to systematically allocate resources to gather relevant intelligence. The CISO has emphasized that simply collecting data is not enough; the team must focus on assigning specific personnel, tools, and time to gather intelligence that aligns with the organization's most pressing security concerns, such as fraud detection, phishing campaigns, and nation-state threats targeting financial transactions. As part of this structured approach, the team must determine who will be responsible for collecting intelligence, what sources will be monitored, and how frequently data should be gathered. This step ensures that the right resources are applied to the most relevant intelligence efforts. What is this process called?