PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #61
You need to augment your organization's existing Security Command Center (SCC) implementation with additional detectors. You have a list of known IOCs and would like to include external signals for…
The correct answer is A. Create an Event Threat Detection custom module using the "Configurable Bad IP" template. The correct approach is to create an Event Threat Detection (ETD) custom module using the "Configurable Bad IP" template. This allows you to ingest known IOCs, including external threat intelligence signals, and generate detections when these IOCs are observed in your…
Question
You need to augment your organization's existing Security Command Center (SCC) implementation with additional detectors. You have a list of known IOCs and would like to include external signals for this capability to ensure broad detection coverage. What should you do?
Options
- ACreate an Event Threat Detection custom module using the "Configurable Bad IP" template.
- BCreate a Security Health Analytics (SHA) custom module using the compute address resource.
- CCreate a custom posture for your organization that combines the prebuilt Event Threat Detection
- DCreate a custom log sink with internal and external IP addresses from threat intelligence. Use the
How the community answered
(48 responses)- A77% (37)
- B6% (3)
- C13% (6)
- D4% (2)
Explanation
The correct approach is to create an Event Threat Detection (ETD) custom module using the "Configurable Bad IP" template. This allows you to ingest known IOCs, including external threat intelligence signals, and generate detections when these IOCs are observed in your environment, augmenting SCC's built-in detection capabilities.
Topics
Community Discussion
No community discussion yet for this question.