Question

Difficulty: MediumThreat Intelligence Sources and Research

Match each threat intelligence source type to its primary operational use case or intelligence characteristic in an enterprise security framework.

  • Open-Source Intelligence (OSINT)Publicly accessible telemetry, code repositories, security blogs, and vulnerability databases used for broad contextual research.
  • Information Sharing and Analysis Center (ISAC)Sector-specific cyber threat collaboration network enabling peer institutions to share threat indicators and mitigation strategies.
  • Dark Web Threat IntelligenceSpecialized intelligence gathered from hidden services and illicit forums to monitor credential exposures and targeted data leaks.
  • Commercial/Proprietary Threat FeedVendor-managed, high-confidence tactical threat indicators provided under a paid service model for automated ingestion.

Answer

Open-Source Intelligence (OSINT) matches publicly accessible research repositories; ISAC matches sector-specific peer sharing networks; Dark Web Intelligence matches monitoring of hidden services for credential exposures; Commercial feeds match vendor-managed paid tactical indicator streams.
Each threat intelligence source type is accurately mapped to its primary delivery model and operational scope: OSINT uses public data, ISACs facilitate sector-specific peer collaboration, Dark Web intelligence monitors illicit underground communities, and Commercial feeds provide paid, automated tactical data streams.

Step-by-Step Solution

1
Analyze Open-Source Intelligence (OSINT)
Identified as freely available public data, matching open telemetry and code repositories.
OSINT encompasses all publicly available sources requiring no proprietary access.
2
Analyze Information Sharing and Analysis Centers (ISACs)
Identified as sector-specific peer sharing organizations.
ISACs focus on industry-wide collaborative threat intelligence.
3
Analyze Dark Web Threat Intelligence
Identified as intelligence gathered from hidden services and illicit market sites.
Dark web monitoring targets underground forums and leaked data.
4
Analyze Commercial/Proprietary Feeds
Identified as vendor-supplied, paid feeds with high confidence for automated ingestion.
Commercial feeds provide actionable, structured indicators backed by service contracts.

Key Concept

Classification and Operational Applications of Threat Intelligence Sources
Rate this question