During a ransomware response, your SOC prepares a set of file hashes and C2 IPs for an industry ISAC. The incident includes customer personal data and internal hostnames. Which action best supports responsible external sharing of the indicators?
Select an answer to reveal the explanation.
Short Explanation
Think of external sharing like passing a note in class: you want the right info to reach the right people, not the whole notebook. Marking the caveat and sending only the needed indicators keeps partners useful without leaking customer PII or internal names. That is responsible threat intel, not just dumping everything.
Full Explanation
Responsible external indicator sharing balances defensive value against confidentiality and minimization. An analyst should determine the audience, apply an agreed handling restriction such as a traffic-light marking, and release only indicators that enable partner detection, such as hashes, domains, or IPs. This preserves trust and supports community defense without unrestricted disclosure.
Sharing a complete incident report fails because full reports often contain customer personal data, internal asset names, forensic notes, and response details that are not needed for detection sharing and may create privacy, legal, or operational risk. Withholding all indicators until legal approval also fails because legal review does not eliminate the need for timely, bounded information sharing; the issue is not that sharing is prohibited, but that it must be scoped and protected. Public posting on an open forum fails because malicious indicators can still be sensitive, especially when tied to a named organization or ongoing investigation; public distribution removes handling controls and can aid attackers in testing evasion.
Exam caveat: choose the answer that pairs external sharing with a handling caveat and minimal necessary indicators, not maximal disclosure or blanket refusal. Operational check: before sending indicators to an ISAC or partner, confirm the recipient, redact nonessential identifiers, apply the agreed traffic-light marking, and use an approved secure channel.