A threat intelligence analyst wants to measure the quality of IOCs being consumed by the SIEM. Which metric most accurately reflects IOC quality in operational use?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because IOC quality is measured operationally by how accurately they detect real threats (true positive rate), how often they generate noise (false positive rate), how current they are (age), and how specific versus generic they are; high-quality IOCs have high true-positive rates with low false positives. A is wrong because volume of IOCs does not indicate quality; many feeds contain large numbers of stale or low-fidelity indicators.
Full explanation below image
Full Explanation
B is correct because IOC quality is measured operationally by how accurately they detect real threats (true positive rate), how often they generate noise (false positive rate), how current they are (age), and how specific versus generic they are; high-quality IOCs have high true-positive rates with low false positives. A is wrong because volume of IOCs does not indicate quality; many feeds contain large numbers of stale or low-fidelity indicators. C is wrong because cost is a commercial factor; expensive feeds can still contain poor-quality indicators. D is wrong because contributor count reflects the crowd-sourced nature of a platform but not the accuracy or relevance of individual indicators.