A threat intelligence analyst receives a report indicating that a specific APT group is targeting organizations in the same industry sector using spear-phishing emails with malicious PDF attachments. How should a defensive SOC operationalize this intelligence?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because operationalizing threat intelligence means converting threat reports into concrete defensive actions: extracting technical indicators for automated detection, updating email security controls, adding known malicious domains/IPs to blocklists, and conducting targeted user awareness to recognize the specific attack style described. A is wrong because simply publishing a report without extracting actionable controls provides no defensive benefit.
Full explanation below image
Full Explanation
B is correct because operationalizing threat intelligence means converting threat reports into concrete defensive actions: extracting technical indicators for automated detection, updating email security controls, adding known malicious domains/IPs to blocklists, and conducting targeted user awareness to recognize the specific attack style described. A is wrong because simply publishing a report without extracting actionable controls provides no defensive benefit. C is wrong because contacting threat actors directly is not a defensive strategy and is potentially dangerous. D is wrong because shutting down email eliminates a critical business communication channel; targeted controls are more appropriate than blanket disruption.