ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 120 - CS0-003 discussion

Report
Export

Which of the following would help an analyst to quickly find out whether the IP address in a SIEM alert is a known-malicious IP address?

A.
Join an information sharing and analysis center specific to the company's industry.
Answers
A.
Join an information sharing and analysis center specific to the company's industry.
B.
Upload threat intelligence to the IPS in STIX/TAXII format.
Answers
B.
Upload threat intelligence to the IPS in STIX/TAXII format.
C.
Add data enrichment for IPS in the ingestion pipleline.
Answers
C.
Add data enrichment for IPS in the ingestion pipleline.
D.
Review threat feeds after viewing the SIEM alert.
Answers
D.
Review threat feeds after viewing the SIEM alert.
Suggested answer: C

Explanation:

The best option to quickly find out whether the IP address in a SIEM alert is a known-malicious IP address is C. Add data enrichment for IPS in the ingestion pipeline.

Data enrichment is the process of adding more information and context to raw data, such as IP addresses, by using external sources. Data enrichment can help analysts to gain more insights into the nature and origin of the threats they face, and to prioritize and respond to them accordingly. Data enrichment for IPS (Intrusion Prevention System) means that the IPS can use enriched data to block or alert on malicious traffic based on various criteria, such as geolocation, reputation, threat intelligence, or behavior. By adding data enrichment for IPS in the ingestion pipeline, analysts can leverage the IPS's capabilities to filter out known-malicious IP addresses before they reach the SIEM, or to tag them with relevant information for further analysis. This can save time and resources for the analysts, and improve the accuracy and efficiency of the SIEM.

The other options are not as effective or efficient as data enrichment for IPS in the ingestion pipeline. Joining an information sharing and analysis center (ISAC) specific to the company's industry (A) can provide valuable threat intelligence and best practices, but it may not be timely or comprehensive enough to cover all possible malicious IP addresses. Uploading threat intelligence to the IPS in STIX/TAXII format (B) can help the IPS to identify and block malicious IP addresses based on standardized indicators of compromise, but it may require manual or periodic updates and integration with the SIEM. Reviewing threat feeds after viewing the SIEM alert (D) can help analysts to verify and contextualize the malicious IP addresses, but it may be too late or too slow to prevent or mitigate the damage. Therefore, C is the best option among the choices given.

asked 02/10/2024
Michele Lorengo
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first