A vendor shares indicators marked TLP:AMBER+STRICT. How should the SOC handle them? In the alert triage phase, Which action gives the analyst the clearest next triage step?
TLP:AMBER+STRICT restricts sharing to the recipient organisation on a need-to-know basis.
Why this answer
TLP:AMBER+STRICT restricts sharing to individuals within the organization who have a specific need to know, and prohibits any wider redistribution. In the alert triage phase, using the indicators internally ensures the SOC can investigate and respond without violating the information-sharing constraints set by the vendor, which is a mandatory security practice, not optional.
Exam trap
CompTIA often tests the misconception that TLP markings are merely advisory or optional, leading candidates to choose 'ignore' or 'publish' options, when in fact TLP is a mandatory handling framework with strict enforcement requirements.
How to eliminate wrong answers
Option A is wrong because TLP markings are mandatory for handling sensitive threat intelligence; ignoring them would violate security policies and potentially expose the organization to legal or operational risks. Option B is wrong because publishing TLP:AMBER+STRICT indicators on a public GitHub repository directly violates the strict no-redistribution rule and could compromise ongoing investigations or expose the vendor's sources. Option C is wrong because sending the indicators to all customers, even if they are internal, violates the 'need to know' restriction of TLP:AMBER+STRICT, which limits sharing to only those individuals directly involved in the response.