Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Cisco Conducting Threat Hunting and Defending using Cisco Technologies for Cybersecurity 300-220 CBRTHD 300-220 Question # 7 Topic 1 Discussion

Cisco Conducting Threat Hunting and Defending using Cisco Technologies for Cybersecurity 300-220 CBRTHD 300-220 Question # 7 Topic 1 Discussion

300-220 Exam Topic 1 Question 7 Discussion:
Question #: 7
Topic #: 1

A SOC analyst using Cisco security tools wants to differentiatethreat huntingfromtraditional detection engineering. Which activity BEST represents threat hunting rather than detection engineering?


A.

Creating a SIEM rule to alert on known malicious domains


B.

Tuning EDR alerts to reduce false positives


C.

Formulating a hypothesis to search for credential misuse without alerts


D.

Blocking IP addresses based on Talos intelligence


Get Premium 300-220 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.