nerdexam
Cisco

300-220 · Question #59

Changes to a detection methodology to augment analytical and process gaps might include: (Choose two)

The correct answer is B. Integrating threat intelligence feeds C. Implementing behavioral analysis techniques. Integrating threat intelligence feeds (B) closes analytical gaps by providing curated, up-to-date data on known adversary tactics, indicators of compromise, and emerging threats - information a detection system wouldn't discover on its own. Implementing behavioral analysis (C)…

Threat Hunting Techniques

Question

Changes to a detection methodology to augment analytical and process gaps might include:

(Choose two)

Options

  • ADecreasing the use of automation and machine learning
  • BIntegrating threat intelligence feeds
  • CImplementing behavioral analysis techniques
  • DRelying solely on signature-based detection

How the community answered

(34 responses)
  • A
    15% (5)
  • B
    79% (27)
  • D
    6% (2)

Explanation

Integrating threat intelligence feeds (B) closes analytical gaps by providing curated, up-to-date data on known adversary tactics, indicators of compromise, and emerging threats - information a detection system wouldn't discover on its own. Implementing behavioral analysis (C) addresses process gaps by identifying anomalous activity patterns rather than relying on pre-known signatures, catching novel or evasive attacks that signature-based tools miss. Together, these two methods complement each other: intelligence feeds provide context about what to look for, while behavioral analysis catches how threats act even when they're unknown.

Why the distractors are wrong:

  • A is the opposite of good practice - automation and ML increase detection coverage and reduce analyst fatigue, not diminish it.
  • D is a known weakness, not an improvement; signature-based detection alone misses zero-days and polymorphic malware entirely.

Memory tip: Think "augment = add capability." Both B and C add new detection dimensions (external intelligence + behavior patterns), while A and D reduce or limit them - elimination by direction works well here.

Topics

#Threat Intelligence Integration#Behavioral Analysis#Detection Methodology#Detection Augmentation

Community Discussion

No community discussion yet for this question.

Full 300-220 Practice