Your SOC analyst team distributes a weekly threat-intelligence package to network and endpoint teams. After one week, the network team reports that several indicators caused noisy alerts, while the endpoint team says the package missed a malware family it was tracking. The analyst lead wants to adjust requirements and improve the next package. Which intelligence lifecycle stage is needed now?
Select an answer to reveal the explanation.
Short Explanation
Think of the intelligence cycle like a recipe: you serve the meal, then ask whether it was too salty. Feedback is the stage that tells you what worked and what didn't, so the next report gets sharper. Skip it, and you keep serving the same under-seasoned intel.
Full Explanation
The intelligence lifecycle is a closed loop, not a linear handoff. After an analyst produces and shares a report, the feedback stage captures whether consumers used the intelligence, whether it answered their questions, whether indicators were actionable, and whether collection or analysis assumptions need adjustment. That stage improves future collection priorities, processing methods, and dissemination formats. Dissemination is wrong because sending the report completes delivery but does not by itself measure usefulness or correct the process. Analysis is wrong because it transforms raw data into meaningful intelligence before sharing, not after delivery. Collection is wrong because it gathers raw information in response to requirements, not evaluates whether the delivered intelligence helped. Processing is wrong because it converts collected data into usable formats, such as normalized indicators or dashboards, rather than judging consumer outcomes. Exam caveat: if the stem asks how to improve future intelligence use, choose feedback, not the stage that merely delivers or creates the report. Operational check: add a short consumer survey to each intelligence package asking whether the indicators were used, false positives, and missing context.