XDR-ANALYST · Question #94
When conducting threat hunting using IOC data, what actions are typically taken? (Choose two)
The correct answer is C. Query historical telemetry data D. Match IOCs against threat intelligence feeds. Threat hunting involves querying historical telemetry to find past activity related to IOCs and matching IOCs against threat intelligence to validate and enrich findings. Isolation and firewall updates are response actions, not hunting steps.
Question
When conducting threat hunting using IOC data, what actions are typically taken? (Choose two)
Options
- AIsolate endpoints based on findings
- BExport indicators to CSV for firewall updates
- CQuery historical telemetry data
- DMatch IOCs against threat intelligence feeds
How the community answered
(29 responses)- A10% (3)
- B7% (2)
- C83% (24)
Explanation
Threat hunting involves querying historical telemetry to find past activity related to IOCs and matching IOCs against threat intelligence to validate and enrich findings. Isolation and firewall updates are response actions, not hunting steps.
Topics
Community Discussion
No community discussion yet for this question.