300-215 Question 155
Select 3You are a cybersecurity analyst monitoring threat intelligence feeds integrated into Cisco SecureX. During your investigation, you notice a cluster of indicators of compromise (IOCs) including specific IP addresses, domain names, and file hashes from an external threat feed. You also find behavioral patterns indicating an attempt to bypass authentication mechanisms within your internal logs. What should you do next to prioritize and respond to this potential threat?
- A
Correlate the external IOCs with internal logs to identify matching activities within your network.
- B
Block all IP addresses, domain names, and file hashes from the external feed without further analysis.
- C
Investigate the internal Indicators of Attack (IOAs) for evidence of lateral movement or privilege escalation.
- D
Ignore the external threat feed until confirmed as a direct threat to your organization.
- E
Leverage Cisco Threat Grid to analyze suspicious files involved in the activity.
Show answer and explanation
Correct answers: A, C, E
Explanation
To effectively prioritize and respond to a potential threat, it is critical to correlate external IOCs with internal data to determine relevance, investigate behavioral Indicators of Attack (IOAs) to detect active threats, and leverage tools like Cisco Threat Grid for deeper analysis. This comprehensive approach ensures informed decision-making and minimizes the risk of overlooking significant threats.
- A. Correct.
Correlating external IOCs with internal logs is critical to determine if the threat has already infiltrated your network or is attempting to do so.
- B. Incorrect.
Blocking all external IOCs without analysis may lead to unnecessary disruptions or false positives, as not all IOCs are directly relevant to your environment.
- C. Correct.
Investigating IOAs (behavioral patterns) is essential to understand if the attackers are actively exploiting vulnerabilities or attempting unauthorized activities within your network.
- D. Incorrect.
Ignoring external threat intelligence without validation could result in missed opportunities to detect and mitigate potential threats.
- E. Correct.
Using Cisco Threat Grid to analyze suspicious files allows for deeper investigation into malware behavior, providing actionable intelligence for response.