A structured threat hunt using Cisco Secure Network Analytics confirms abnormal internal SMB traffic consistent with lateral movement. Which action should occur NEXT to improve organizational security posture?
The correct answer is document findings and create permanent detections. While containment actions are necessary, they are incident response tasks, not threat hunting outcomes.
Cisco's threat hunting lifecycle emphasizes that once malicious behavior is confirmed, teams must:
Document attacker techniques
Identify detection gaps
Convert findings into automated detections
Options A and B are tactical responses that address the current incident but do not prevent recurrence. Option D delays improvement and increases risk.
Operationalizing hunt findings ensures:
Repeated attacker behavior is detected automatically
Future dwell time is reduced
SOC maturity increases
This step directly aligns with the CBRTHD blueprint's focus on continuous improvement and feedback loops between hunting and monitoring.
Therefore, Option C is the correct answer.
Isreal
3 days agoTayna
8 days agoGraham
13 days agoKallie
19 days agoRasheeda
24 days agoPaola
29 days agoDortha
1 month agoBarbra
1 month agoBilly
1 month agoKirby
2 months agoSylvia
2 months agoTy
2 months agoPrincess
2 months agoChauncey
2 months ago