nerdexam
Cisco

350-701 · Question #703

Which action adds IOCs to customize detections for a new attack?

The correct answer is B. Upload the 10Cs into the Installed Endpoint IOC feature within Cisco Secure Endpoint. To customize detections for new attacks by adding Indicators of Compromise (IOCs) in Cisco Secure Endpoint, an administrator must upload these IOCs directly into the platform's dedicated IOC management feature.

Submitted by takeshi77· Mar 30, 2026

Question

Which action adds IOCs to customize detections for a new attack?

Options

  • AUse the initiate Endpoint 1OC scan feature to gather the IOC information and push it to clients.
  • BUpload the 10Cs into the Installed Endpoint IOC feature within Cisco Secure Endpoint.
  • CAdd a custom advanced detection to include the 1OCs needed within Cisco Secure Endpoint.
  • DModify the base policy within Cisco Secure Endpoint to include simple custom detections.

How the community answered

(63 responses)
  • A
    16% (10)
  • B
    71% (45)
  • C
    8% (5)
  • D
    5% (3)

Why each option

To customize detections for new attacks by adding Indicators of Compromise (IOCs) in Cisco Secure Endpoint, an administrator must upload these IOCs directly into the platform's dedicated IOC management feature.

AUse the initiate Endpoint 1OC scan feature to gather the IOC information and push it to clients.

The "initiate Endpoint IOC scan feature" is used to actively scan endpoints for *existing* IOCs, not to *add* new IOCs into the system for future detection.

BUpload the 10Cs into the Installed Endpoint IOC feature within Cisco Secure Endpoint.Correct

Cisco Secure Endpoint provides a dedicated feature for uploading and managing custom Indicators of Compromise (IOCs), such as file hashes, IP addresses, or domain names, which allows administrators to define specific patterns for detection and customize the endpoint's threat intelligence for new or targeted attacks.

CAdd a custom advanced detection to include the 1OCs needed within Cisco Secure Endpoint.

While IOCs are used in custom detections, the most direct and specific action to *add* the IOCs themselves is typically through an upload mechanism into a dedicated IOC management feature, rather than a generic "add custom advanced detection."

DModify the base policy within Cisco Secure Endpoint to include simple custom detections.

Modifying the base policy might enable or reference custom detections, but it is not the direct action for *adding* the actual IOCs themselves; IOCs are usually defined and managed in a separate section before being applied via policies.

Concept tested: Cisco Secure Endpoint Custom IOC Management

Source: https://docs.endpoint.security.cisco.com/en/latest/admin/ioc/create.html

Topics

#Cisco Secure Endpoint#IOC management#Custom detections

Community Discussion

No community discussion yet for this question.

Full 350-701 Practice