A continuous security monitoring program receives threat intelligence indicating an APT group is actively exploiting a zero-day in VPN concentrators. The intelligence includes IOCs such as specific IP addresses and file hashes. What is the MOST effective immediate use of this intelligence?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — a is correct because operationalizing threat intelligence means immediately ingesting IOCs into detection platforms, hunting for historical evidence of compromise, and configuring proactive alerting. B is wrong because executive awareness without technical action does not reduce risk.
Full explanation below image
Full Explanation
A is correct because operationalizing threat intelligence means immediately ingesting IOCs into detection platforms, hunting for historical evidence of compromise, and configuring proactive alerting. B is wrong because executive awareness without technical action does not reduce risk. C is wrong because waiting for a patch misses the opportunity to detect existing compromises; blocking on IOCs provides immediate value. D is wrong because blocking all VPN access causes unacceptable business impact when targeted controls are available.