312-39 · Question #12
You are a Threat Hunter in an IT company's security team working to enhance threat hunting capabilities. You observed that relying solely on traditional security alerts often results in missed…
The correct answer is D. Data Integration. This scenario is centered on combining multiple heterogeneous data sources into a single analytical view so that signals can be correlated into higher-confidence detections. That is the core of data integration: ingesting external intelligence (malicious…
Question
You are a Threat Hunter in an IT company’s security team working to enhance threat hunting capabilities. You observed that relying solely on traditional security alerts often results in missed detections of sophisticated threats. To strengthen your approach, you decide to incorporate multiple data sources, including external threat intelligence feeds, internal security logs, network traffic data, and endpoint telemetry. To efficiently process this vast amount of data, you implement a new tool that can aggregate, normalize, and correlate threat intelligence with internal telemetry to gain a more holistic understanding of emerging threats and enhance detection accuracy. What key threat detection capability is being leveraged in this scenario?
Options
- BIntelligence Buy-In
- CThreat Trending
- DData Integration
How the community answered
(57 responses)- B5% (3)
- C12% (7)
- D82% (47)
Explanation
This scenario is centered on combining multiple heterogeneous data sources into a single analytical view so that signals can be correlated into higher-confidence detections. That is the core of data integration: ingesting external intelligence (malicious IPs/domains/hashes/TTPs) and internal telemetry (endpoint events, authentication, network flows, DNS, proxy, cloud logs), then normalizing and correlating them to detect activity that would be missed if each source were analyzed in isolation. In threat hunting, integration enables pivoting and validation: an external indicator becomes meaningful when matched to internal events, and internal anomalies become higher priority when they align with known adversary behaviors. “Threat reports” are outputs, not the underlying capability. “Intelligence buy-in” is governance and stakeholder support, not a technical detection capability. “Threat trending” focuses on patterns over time (frequency, prevalence), which can inform strategy but does not directly describe the aggregation/normalization/correlation capability emphasized here. For SOC analysts, data integration is what allows efficient triage and hunting at scale, reduces blind spots, and improves detection fidelity by cross-validating evidence across endpoints, identity, network, and external intelligence.
Topics
Community Discussion
No community discussion yet for this question.