After a phishing-to-lateral-movement incident is closed, the analyst has confirmed IOCs, MITRE ATT&CK techniques, and EDR telemetry showing the attacker's behavior. What should the analyst do next to close the intelligence loop and improve future detection?
Select an answer to reveal the explanation.
Short Explanation
Think of threat intel like a fishing net: every closed incident tells you which holes are leaking. If you just file the report or wait for a vendor signature, you don't tighten the net. You need to push confirmed IOCs, TTPs, and hunting lessons back into detection logic so the next hunt starts smarter.
Full Explanation
Closed-loop threat intelligence means investigation outcomes become inputs to the intelligence cycle: confirmed indicators, observed techniques, false positives, and missed detections inform collection priorities, enrichment, and detection engineering. When an incident is closed, the analyst should translate what was learned into concrete feedback: feed IOCs and TTPs to the intel team, update Sigma or hunting queries, and record which telemetry helped or failed. This turns one case into better future detection rather than a static ticket.
Archiving the report preserves evidence but does not change detection logic or intelligence priorities. Waiting for a vendor signature is reactive and may never happen; it also skips internal hunting value. Adding generic phishing reports increases noise without using confirmed incident specifics to tune rules.
Exam caveat: CompTIA often asks for the action that improves the intelligence cycle, not the best administrative closure step. Operational check: Compare the incident's confirmed TTPs to current detection rules and document one rule, query, or collection change that would have improved detection.