350-701 · Question #703
Which action adds IOCs to customize detections for a new attack?
The correct answer is B. Upload the 10Cs into the Installed Endpoint IOC feature within Cisco Secure Endpoint. To customize detections for new attacks by adding Indicators of Compromise (IOCs) in Cisco Secure Endpoint, an administrator must upload these IOCs directly into the platform's dedicated IOC management feature.
Question
Which action adds IOCs to customize detections for a new attack?
Options
- AUse the initiate Endpoint 1OC scan feature to gather the IOC information and push it to clients.
- BUpload the 10Cs into the Installed Endpoint IOC feature within Cisco Secure Endpoint.
- CAdd a custom advanced detection to include the 1OCs needed within Cisco Secure Endpoint.
- DModify the base policy within Cisco Secure Endpoint to include simple custom detections.
How the community answered
(63 responses)- A16% (10)
- B71% (45)
- C8% (5)
- D5% (3)
Why each option
To customize detections for new attacks by adding Indicators of Compromise (IOCs) in Cisco Secure Endpoint, an administrator must upload these IOCs directly into the platform's dedicated IOC management feature.
The "initiate Endpoint IOC scan feature" is used to actively scan endpoints for *existing* IOCs, not to *add* new IOCs into the system for future detection.
Cisco Secure Endpoint provides a dedicated feature for uploading and managing custom Indicators of Compromise (IOCs), such as file hashes, IP addresses, or domain names, which allows administrators to define specific patterns for detection and customize the endpoint's threat intelligence for new or targeted attacks.
While IOCs are used in custom detections, the most direct and specific action to *add* the IOCs themselves is typically through an upload mechanism into a dedicated IOC management feature, rather than a generic "add custom advanced detection."
Modifying the base policy might enable or reference custom detections, but it is not the direct action for *adding* the actual IOCs themselves; IOCs are usually defined and managed in a separate section before being applied via policies.
Concept tested: Cisco Secure Endpoint Custom IOC Management
Source: https://docs.endpoint.security.cisco.com/en/latest/admin/ioc/create.html
Topics
Community Discussion
No community discussion yet for this question.