Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

ECCouncil Certified SOC Analyst (CSA v2) 312-39 Question # 31 Topic 4 Discussion

ECCouncil Certified SOC Analyst (CSA v2) 312-39 Question # 31 Topic 4 Discussion

312-39 Exam Topic 4 Question 31 Discussion:
Question #: 31
Topic #: 4

A mid-sized financial institution’s SOC is overwhelmed by thousands of daily alerts, many based on Indicators of Compromise (IoCs) such as suspicious IPs, hashes, and domains. These alerts lack context about whether they truly pose a threat. Analysts waste time on low-priority incidents while severe threats may be missed. The team lacks tools and intelligence to correlate IoCs with real-world threats, making prioritization difficult and causing alert fatigue. Which poses the greatest challenge in this environment?


A.

Malware-centric and CTI are not equivalent


B.

Information overload


C.

Budget and enterprise skill


D.

Distinguishing IoC from CTI


Get Premium 312-39 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.