nerdexam
Cisco

300-220 · Question #5

The integration of which products would most enhance analytical capabilities for threat hunting?

The correct answer is C. SIEM, EDR, and threat intelligence platforms. Integrating SIEM, EDR, and threat intelligence platforms creates a unified analytical ecosystem where log aggregation (SIEM), endpoint telemetry (EDR), and contextual threat data work together - giving threat hunters correlated, enriched visibility across the environment that…

Threat Hunting Fundamentals

Question

The integration of which products would most enhance analytical capabilities for threat hunting?

Options

  • AStandalone antivirus solutions
  • BDisconnected SIEM and endpoint detection and response (EDR) platforms
  • CSIEM, EDR, and threat intelligence platforms
  • DUncoordinated firewall and intrusion prevention systems

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    92% (24)

Explanation

Integrating SIEM, EDR, and threat intelligence platforms creates a unified analytical ecosystem where log aggregation (SIEM), endpoint telemetry (EDR), and contextual threat data work together - giving threat hunters correlated, enriched visibility across the environment that no single tool can provide alone.

Why the distractors fail:

  • A (Standalone antivirus): Antivirus is reactive and signature-based, offering no behavioral analytics or cross-environment correlation needed for proactive hunting.
  • B (Disconnected SIEM and EDR): Even good tools in silos create blind spots - the lack of integration means analysts manually bridge gaps, slowing detection and missing chained attack patterns.
  • D (Uncoordinated firewalls and IPS): These are perimeter controls, not analytical platforms; without coordination and enrichment they generate noise rather than hunting-ready intelligence.

Memory tip: Think "SET" - SIEM + EDR + Threat Intel = the analytical triad. Just as a physical hunt requires tracking, eyes on the ground, and a map, threat hunting requires logs (SIEM), endpoint behavior (EDR), and adversary context (threat intel) - all connected.

Topics

#SIEM#EDR#Threat Intelligence#Tool Integration

Community Discussion

No community discussion yet for this question.

Full 300-220 Practice