Soru

Zorluk: KolayThreat Intelligence Sources and Research

A security analyst needs to gather freely available threat indicators and standardized software vulnerability data without incurring commercial licensing or subscription costs. Which TWO of the following threat intelligence sources should the analyst utilize?

  1. Open-Source Intelligence (OSINT)Cevap
  2. B
    Proprietary commercial threat intelligence feeds
  3. Public vulnerability databases (such as NVD and CVE lists)Cevap
  4. D
    Internal SIEM correlation log repositories
  5. E
    Production network honeypots

Cevap

The analyst should utilize Open-Source Intelligence (OSINT) and public vulnerability databases (such as NVD and CVE lists).
Open-Source Intelligence (OSINT) and public vulnerability databases (like NVD/CVE) both provide freely available, publicly accessible threat data and vulnerability details without requiring paid subscriptions or proprietary vendor tools.

Adım Adım Çözüm

1
Identify the constraints specified in the scenario
The requirements demand threat intelligence sources that are publicly available, free of charge, and provide threat indicators or software vulnerability data.
Filtering intelligence sources by cost and public accessibility narrows the valid choices.
2
Evaluate publicly available threat intelligence sources
Open-Source Intelligence (OSINT) provides threat indicators from open media, web feeds, and repositories. Public vulnerability databases (such as the NVD/CVE repository) supply free, standardized vulnerability information.
Both sources fulfill the criteria of being publicly accessible and cost-free.
3
Exclude paid, internal, or active detection mechanisms
Proprietary feeds require subscriptions, internal SIEM logs are localized security telemetry, and honeypots are active internal deception tools.
These alternatives either incur financial costs or fail to qualify as external research intelligence sources.

Anahtar Kavram

Threat Intelligence Sources and Research
Bu soruyu puanla