nerdexam
CompTIA

CS0-003 · Question #533

An analyst would like to start automatically ingesting IoCs into the EDR tool. Which of the following sources would be the most cost effective for the analyst to use?

The correct answer is A. Government bulletins. Government bulletins are generally the most cost-effective source for automatically ingesting Indicators of Compromise (IoCs) into an EDR tool.

Submitted by takeshi77· Mar 6, 2026Security operations

Question

An analyst would like to start automatically ingesting IoCs into the EDR tool. Which of the following sources would be the most cost effective for the analyst to use?

Options

  • AGovernment bulletins
  • BSocial media
  • CDark web
  • DBlogs

How the community answered

(15 responses)
  • A
    93% (14)
  • D
    7% (1)

Why each option

Government bulletins are generally the most cost-effective source for automatically ingesting Indicators of Compromise (IoCs) into an EDR tool.

AGovernment bulletinsCorrect

Government bulletins (e.g., CISA advisories, national CERTs) often provide IoCs free of charge in standardized, machine-readable formats (like STIX/TAXII feeds) that are designed for automated ingestion, making them highly cost-effective and reliable.

BSocial media

Social media can contain IoCs but often requires significant manual effort for curation, validation, and conversion into an ingestible format, making it less cost-effective for automated, reliable ingestion.

CDark web

The dark web may contain valuable IoCs, but accessing and processing this information is legally and technically complex, carries significant risks, and is not cost-effective or practical for automated, regular ingestion.

DBlogs

Blogs can provide IoCs, but like social media, they are typically in unstructured formats, requiring manual effort for extraction and validation, which makes them less suitable for cost-effective automated ingestion.

Concept tested: Cost-effective IoC sources

Source: https://www.cisa.gov/resources-tools/resources/cyber-threat-intelligence

Topics

#IoC ingestion#EDR#Threat intelligence sources#Cost-effectiveness

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice