Question

Difficulty: HardThreat Intelligence Sources and Research

A lead security analyst at a online retail enterprise is evaluating threat intelligence options to proactively detect compromised corporate credentials being offered for sale on subterranean marketplaces. The organization requires actionable, curated threat feeds with tailored risk scoring and automated API integration to ingest indicators of compromise (IOCs) without dedicating internal staff to manually monitor dark web forums. Which threat intelligence source type should the analyst recommend to meet these requirements?

  1. Commercial threat intelligence feedAnswer
  2. B
    Open-source intelligence (OSINT)
  3. C
    Sector-specific Information Sharing and Analysis Center (ISAC)
  4. D
    National Vulnerability Database (NVD)

Answer

Commercial threat intelligence feed
Commercial threat intelligence feeds are subscription-based services provided by security vendors who deploy dedicated researchers and automated tools to monitor dark web forums, paste sites, and subterranean channels. They curate this raw data, enrich it with contextual risk scores, and deliver actionable indicators automatically through API integrations, fulfilling all specified organizational criteria.

Step-by-Step Solution

1
Analyze the operational requirements
Identified key requirements: dark web monitoring, curated risk scoring, automated API integration, and no manual internal research overhead.
The enterprise needs a turnkey intelligence product rather than raw data collection.
2
Evaluate intelligence source attributes
Commercial threat intelligence vendors specialize in specialized deep/dark web monitoring, raw data processing, contextual enrichment, and automated IOC delivery via structured APIs.
Paid commercial feeds offload manual scraping and vetting from internal SOC teams.
3
Compare against alternative options
OSINT lacks deep subterranean monitoring guarantees; ISACs focus on peer sharing rather than credential scraping services; NVD catalogs software flaws rather than compromised account data.
Commercial threat intelligence is the only option satisfying all constraints.

Key Concept

Distinguishing characteristics and operational use cases of Commercial/Proprietary Threat Intelligence feeds compared to OSINT, ISACs, and Vulnerability Databases.
Estimated Time:2m 0s
Rate this question