300-215 · Question #6
Refer to the exhibit. Which two actions should be taken based on the intelligence information? (Choose two.)
The correct answer is B. Add a SIEM rule to alert on connections to identified domains. D. Block network access to identified domains. The STIX intelligence feed in the exhibit identifies specific malicious domains, such as: fightcovid19.shop stopcovid19.shop These are categorized as "Malicious FQDN Indicator." The recommended cybersecurity actions when such threat intelligence is received are: Block network…
Question
Refer to the exhibit. Which two actions should be taken based on the intelligence information? (Choose two.)
Exhibit
Options
- ABlock network access to all .shop domains
- BAdd a SIEM rule to alert on connections to identified domains.
- CUse the DNS server to block hole all .shop requests.
- DBlock network access to identified domains.
- ERoute traffic from identified domains to block hole.
How the community answered
(52 responses)- A6% (3)
- B83% (43)
- C2% (1)
- E10% (5)
Explanation
The STIX intelligence feed in the exhibit identifies specific malicious domains, such as: fightcovid19.shop stopcovid19.shop These are categorized as "Malicious FQDN Indicator." The recommended cybersecurity actions when such threat intelligence is received are: Block network access to identified domains: This directly prevents users or systems from communicating with known malicious infrastructure and is a critical first step in threat mitigation. Add a SIEM rule to alert on connections to identified domains: This ensures that any attempted communication with these domains is flagged for immediate review and action, enabling real-time threat detection and incident response.
Topics
Community Discussion
No community discussion yet for this question.
