300-215 Question 156
Select 3Your organization's SOC team receives a threat intelligence feed indicating a recent attack campaign involving malware that exploits vulnerabilities in remote desktop protocol (RDP) services. The feed provides indicators of compromise (IOCs) such as IP addresses, file hashes, and domain names associated with the threat actor. Using Cisco SecureX, what actions should you take to identify potential compromise within your environment?
- A
Use Cisco SecureX Threat Response to query the provided file hashes across endpoint telemetry in your environment.
- B
Cross-reference the IP addresses from the threat intelligence feed with internal firewall and network logs using Cisco Secure Firewall.
- C
Ignore the domain names in the feed, as they are less reliable indicators of compromise.
- D
Ingest the threat intelligence feed into Cisco SecureX to automatically correlate it with security events across your infrastructure.
- E
Manually scan all endpoints for signs of RDP vulnerabilities using Cisco Secure Endpoint.
Show answer and explanation
Correct answers: A, B, D
Explanation
To determine the presence of IOCs and potential compromise, leveraging tools like Cisco SecureX Threat Response and Secure Firewall allows you to correlate threat intelligence feeds with internal data. Automating the ingestion and correlation of IOCs via SecureX enhances the efficiency of your investigation. Ignoring parts of the feed, such as domain names, or relying on manual processes reduces the effectiveness of threat hunting.
- A. Correct.
Using Cisco SecureX Threat Response to query file hashes is a valid action to identify if the malware has been seen on your endpoints.
- B. Correct.
Cross-referencing the IP addresses with firewall and network logs helps determine whether the malicious IPs have communicated with your network.
- C. Incorrect.
Ignoring domain names is incorrect, as they can provide valuable threat intelligence when correlated with DNS or proxy logs.
- D. Correct.
Ingesting the threat intelligence feed into Cisco SecureX allows for automated correlation of IOCs with existing security telemetry, improving detection speed.
- E. Incorrect.
Manually scanning all endpoints is not an efficient use of resources, and Cisco Secure Endpoint provides automated tools for vulnerability detection and IOC correlation.