nerdexam
Cisco

300-220 · Question #124

During which phase of the threat hunting process are threat indicators analyzed and correlated?

The correct answer is B. Analysis. Analysis (B) is correct because this phase is specifically where collected threat indicators are examined, correlated with each other, and interpreted to identify patterns, anomalies, or potential attack activity - turning raw data into meaningful intelligence. Collection (A)…

Threat Hunting Processes

Question

During which phase of the threat hunting process are threat indicators analyzed and correlated?

Options

  • ACollection
  • BAnalysis
  • CInvestigation
  • DRemediation

How the community answered

(51 responses)
  • A
    4% (2)
  • B
    94% (48)
  • C
    2% (1)

Explanation

Analysis (B) is correct because this phase is specifically where collected threat indicators are examined, correlated with each other, and interpreted to identify patterns, anomalies, or potential attack activity - turning raw data into meaningful intelligence.

Collection (A) is wrong because that phase focuses on gathering data from logs, endpoints, and network sources - not making sense of it yet. Investigation (C) occurs after analysis, when a specific confirmed or suspected threat is followed up with deeper, targeted research into scope and impact. Remediation (D) is the final response phase - containment, eradication, and recovery - which happens only after the threat is understood.

Memory tip: Think of the phases in logical order - Collect the data, Analyze what it means, Investigate what you found, Remediate the problem. The word "correlated" is a strong signal for Analysis, since correlation is a data-analysis operation, not a collection or response action.

Topics

#Threat Hunting Phases#Threat Indicators#Analysis and Correlation#Threat Hunting Workflow

Community Discussion

No community discussion yet for this question.

Full 300-220 Practice