Soru

Zorluk: OrtaThreat Intelligence Sources and Research

A security operations center (SOC) analyst is investigating an active phishing campaign. The analyst needs to rapidly collect publicly accessible domain registration details, IP reputation scores, and security blogs without requiring commercial licensing or sector-specific trust memberships. Which of the following intelligence source categories should the analyst consult?

  1. Open-Source Intelligence (OSINT)Cevap
  2. B
    Information Sharing and Analysis Center (ISAC)
  3. C
    Proprietary commercial threat feed
  4. D
    Dark web threat actor forum profiling

Cevap

Open-Source Intelligence (OSINT)
Open-Source Intelligence (OSINT) refers to intelligence collected from publicly available resources, including WHOIS data, public code repositories, DNS records, and open security blogs, fulfilling the analyst's requirement for free and accessible data.

Adım Adım Çözüm

1
Analyze scenario requirements
Identified key parameters: freely accessible, public domain/IP research, no commercial subscription, no closed membership required.
The analyst needs immediate threat context using publicly available resources.
2
Evaluate intelligence source categories against parameters
Open-Source Intelligence (OSINT) fits all criteria as it draws from public domain records, open repositories, and public research.
OSINT is defined by its public availability and accessibility without fee or restrictive membership.

Anahtar Kavram

Threat Intelligence Sources - OSINT vs Closed Sources
Bu soruyu puanla