Soru

Zorluk: ZorThreat Intelligence Sources and Research

A security operations team is refining its threat intelligence research workflow during an active incident investigation involving suspicious PowerShell scripts executed on an endpoint. An analyst needs to correlate newly identified command-and-control (C2) domains against publicly accessible registration data, historic passive DNS records, and peer-reviewed technical blogs without transmitting internal organization telemetry to external partners or incurring subscription fees. Which of the following threat intelligence source categories best satisfies these operational constraints?

  1. Open-Source Intelligence (OSINT)Cevap
  2. B
    Information Sharing and Analysis Center (ISAC) feeds
  3. C
    Commercial or proprietary threat intelligence feeds
  4. D
    National Vulnerability Database (NVD) records

Cevap

Open-Source Intelligence (OSINT) is the correct choice because it relies entirely on publicly available resources such as WHOIS databases, open passive DNS repositories, and public research write-ups without requiring subscription costs or sharing sensitive internal telemetry.
Open-Source Intelligence (OSINT) refers to intelligence derived from publicly accessible information, including WHOIS registries, open passive DNS databases, threat research publications, and code repositories. It allows analysts to research infrastructure indicators freely and passively without transmitting private incident data to third parties.

Adım Adım Çözüm

1
Analyze the operational constraints given in the scenario.
Identified key requirements: zero financial cost (no subscriptions), no outbound sharing of sensitive organization telemetry, and reliance on publicly accessible domain/DNS records.
Threat intelligence source selection must strictly conform to organizational privacy, data-sharing, and budget policies.
2
Evaluate candidate intelligence source categories against the constraints.
OSINT sources (WHOIS, open passive DNS records, public blogs) meet all criteria because they are public, free, and require no inbound/outbound telemetry submission.
OSINT permits passive research using publicly exposed information assets without alerting threat actors or incurring vendor fees.
3
Eliminate incorrect options based on scenario mismatches.
ISAC feeds require industry membership and threat-sharing agreements; commercial feeds require subscription licensing; NVD tracks software vulnerabilities rather than infrastructure/domain IOCs.
Each eliminated source fails either the cost constraint, telemetry-sharing constraint, or data domain relevance requirement.

Anahtar Kavram

Threat Intelligence Sources (OSINT vs. Closed/Proprietary vs. ISAC vs. Vulnerability Databases)
Bu soruyu puanla