Threat intelligence supplies contextual information about adversaries, indicators, infrastructure, vulnerabilities, and attack techniques so security teams can improve detection, investigation, prioritization, and response. Cisco’s Security Reference Architecture explains that integrating threat intelligence and dynamic context improves threat detection and analysis, while the SOC coordinates incident response and remediation. This aligns directly with option A. Access control and authentication are identity and policy-enforcement functions that may consume threat context but are not the purpose of threat intelligence. Traffic analysis is one source of security telemetry, whereas threat intelligence enriches observations from network, endpoint, email, cloud, and identity systems; it is also broader than vulnerability discovery. Regulatory compliance may benefit from stronger monitoring and response, but compliance is an indirect organizational outcome. Therefore, assisting threat monitoring and incident response is the architecturally correct purpose.
================
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit