Cisco Conducting Threat Hunting and Defending using Cisco Technologies for Cybersecurity 300-220 CBRTHD 300-220 Question # 10 Topic 2 Discussion
300-220 Exam Topic 2 Question 10 Discussion:
Question #: 10
Topic #: 2
A SOC using Cisco security technologies wants to measure the success of its threat hunting program over time. Which metric BEST reflects increased threat hunting maturity?
The correct answer isreduction in attacker dwell time. Dwell time measures how long an attacker remains undetected in the environment.
As threat hunting maturity increases:
Detection becomes faster
Behavioral coverage improves
Attackers are identified earlier in the kill chain
Metrics such as alert volume or blocked IPs (Options A and D) do not reflect effectiveness and may even indicate excessive noise. Option B measures inputs, not outcomes.
Cisco’sCBRTHD blueprintfocuses onoutcomes, not activity. Reduced dwell time demonstrates:
Effective hunting
Better visibility
Stronger detection engineering
This metric directly correlates with reduced breach impact and improved resilience.
Therefore,Option Cis the correct and Cisco-aligned answer.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit