Question 1 of 30
In a corporate environment, a threat hunting team is analyzing network traffic logs to identify potential indicators of compromise (IoCs). They notice an unusual spike in outbound traffic to an IP address that is not recognized as part of their regular business operations. The team decides to investigate further by correlating this traffic with user activity logs and endpoint security alerts. Which of the following approaches would best enhance their investigation process?
Implementing a behavioral analysis tool to establish a baseline of normal user activity and detect anomalies.
Relying solely on historical data of previous incidents to identify patterns of malicious behavior.
Focusing exclusively on the IP address in question without considering other network segments or user behaviors.
Conducting a one-time review of the logs without continuous monitoring or follow-up actions.

Preparing for CISCO 350-201 Performing CyberOps Using Core Security Technologies (CBRCOR)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free