200-201 exam dumps

200-201 practice question 21 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 21

Single answer

A cybersecurity operations center receives reports of a new malware campaign targeting financial institutions. The team wants to integrate threat intelligence (TI) into their workflows to enhance their detection and response capabilities. Which action best demonstrates how they should use threat intelligence effectively?

  1. A

    Subscribe to a trusted threat intelligence feed and automate the ingestion of Indicators of Compromise (IOCs) into their SIEM system for correlation.

  2. B

    Rely solely on endpoint detection and response (EDR) tools to detect and mitigate the malware without threat intelligence integration.

  3. C

    Manually review firewall logs for signs of malicious activity and compare them to known threat actor profiles without external threat intelligence.

  4. D

    Ignore external threat intelligence feeds and focus only on internal network traffic analysis.

Show answer and explanation

Correct answer: A

Explanation

Effective use of threat intelligence involves integrating actionable external data, such as IOCs, into existing systems like SIEM for real-time correlation and enhanced detection. This approach enables teams to identify potential threats proactively and respond quickly, improving overall security posture.

  • A. Correct.

    Subscribing to a trusted threat intelligence feed and automating IOC ingestion into the SIEM system allows for real-time correlation and proactive detection of threats, which is a fundamental use case of threat intelligence.

  • B. Incorrect.

    Relying solely on EDR tools without threat intelligence integration limits the team's ability to anticipate and detect threats based on external information, making the approach less effective.

  • C. Incorrect.

    Manually reviewing logs without leveraging external threat intelligence is inefficient and misses the benefits of automated correlation and actionable intelligence.

  • D. Incorrect.

    Ignoring external threat intelligence eliminates a critical layer of security that provides context about emerging threats and global attack trends.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam