nerdexam
Palo_Alto_Networks

XDR-ANALYST · Question #94

When conducting threat hunting using IOC data, what actions are typically taken? (Choose two)

The correct answer is C. Query historical telemetry data D. Match IOCs against threat intelligence feeds. Threat hunting involves querying historical telemetry to find past activity related to IOCs and matching IOCs against threat intelligence to validate and enrich findings. Isolation and firewall updates are response actions, not hunting steps.

Threat Intelligence and Hunting

Question

When conducting threat hunting using IOC data, what actions are typically taken? (Choose two)

Options

  • AIsolate endpoints based on findings
  • BExport indicators to CSV for firewall updates
  • CQuery historical telemetry data
  • DMatch IOCs against threat intelligence feeds

How the community answered

(29 responses)
  • A
    10% (3)
  • B
    7% (2)
  • C
    83% (24)

Explanation

Threat hunting involves querying historical telemetry to find past activity related to IOCs and matching IOCs against threat intelligence to validate and enrich findings. Isolation and firewall updates are response actions, not hunting steps.

Topics

#threat hunting#IOC#threat intelligence#telemetry analysis

Community Discussion

No community discussion yet for this question.

Full XDR-ANALYST Practice