A threat intelligence analyst receives a report from an ISAC (Information Sharing and Analysis Center) containing a list of IP addresses, domains, and file hashes associated with a threat actor targeting the energy sector. How should this intelligence be prioritized for operationalization?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because not all threat intelligence is equally relevant; assessing actor targeting (sector, technology, geography) determines applicability. The Pyramid of Pain prioritization — TTPs are hardest for attackers to change and should drive detection rules; domains and IPs are lower-value and higher decay — guides which indicators to operationalize first and how.
Full explanation below image
Full Explanation
B is correct because not all threat intelligence is equally relevant; assessing actor targeting (sector, technology, geography) determines applicability. The Pyramid of Pain prioritization — TTPs are hardest for attackers to change and should drive detection rules; domains and IPs are lower-value and higher decay — guides which indicators to operationalize first and how. A is wrong because sharing ISAC intelligence externally without authorization violates TLP (Traffic Light Protocol) sharing restrictions. C is wrong because blind blocking without relevance assessment risks blocking legitimate services. D is wrong because quarterly review delays actionable intelligence that may be relevant to imminent attacks.