A security analyst needs to gather freely available threat indicators and standardized software vulnerability data without incurring commercial licensing or subscription costs. Which TWO of the following threat intelligence sources should the analyst utilize?
- Open-Source Intelligence (OSINT)Cevap
- BProprietary commercial threat intelligence feeds
- Public vulnerability databases (such as NVD and CVE lists)Cevap
- DInternal SIEM correlation log repositories
- EProduction network honeypots
Cevap
The analyst should utilize Open-Source Intelligence (OSINT) and public vulnerability databases (such as NVD and CVE lists).
Open-Source Intelligence (OSINT) and public vulnerability databases (like NVD/CVE) both provide freely available, publicly accessible threat data and vulnerability details without requiring paid subscriptions or proprietary vendor tools.
Adım Adım Çözüm
Anahtar Kavram
Threat Intelligence Sources and Research