Soru

Zorluk: OrtaThreat Intelligence Sources and Research

A threat intelligence analyst at a cloud service provider is tasked with obtaining early-warning indicators regarding unpatched, zero-day vulnerabilities currently being offered for sale by illicit actors prior to public disclosure. Which threat intelligence source type should the analyst primarily monitor to fulfill this requirement?

  1. Dark web threat intelligence feedsCevap
  2. B
    Open-Source Intelligence (OSINT) repositories
  3. C
    National Vulnerability Database (NVD) CVE entries
  4. D
    Strategic nation-state threat actor attribution reports

Cevap

Dark web threat intelligence feeds serve as the primary source for monitoring illicit marketplaces and closed underground communities trading unpatched vulnerabilities and zero-day exploits.
Dark web threat intelligence involves monitoring underground markets, specialized forums, and anonymized networks where threat actors actively buy, sell, and share zero-day vulnerabilities, stolen credentials, and custom attack tooling before the broader cybersecurity community becomes aware of them.

Adım Adım Çözüm

1
Analyze the operational intelligence requirement
Identified the core requirement as gathering early-warning threat data on zero-day vulnerabilities being actively commercialized by cybercriminals prior to public release.
The scenario highlights pre-disclosure sales in illicit communities rather than public disclosures or post-incident analysis.
2
Evaluate intelligence source characteristics
Recognized that dark web intelligence specifically monitors onion sites, darknet markets, and invitation-only threat actor forums.
Zero-day sales and criminal trade occur within restricted channels inaccessible through conventional web indexing or public feeds.
3
Select the optimal intelligence source type
Determined that dark web threat intelligence feeds provide the necessary visibility into illicit exploit trading.
Other public sources (such as NVD or OSINT) only register vulnerabilities after public disclosure or CVE assignment.

Anahtar Kavram

Threat Intelligence Sources (Dark Web vs. OSINT vs. Vulnerability Databases)
Tahmini Süre:1m 0s
Bu soruyu puanla