Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-220 Exam - Topic 3 Question 10 Discussion

A structured threat hunt using Cisco Secure Network Analytics confirms abnormal internal SMB traffic consistent with lateral movement. Which action should occur NEXT to improve organizational security posture?
C) Document findings and create permanent detections
A) Isolate the affected hosts immediately
B) Reset all user credentials involved
D) Continue monitoring until more evidence is collected

Cisco 300-220 Exam - Topic 3 Question 10 Discussion

Actual exam question for Cisco's 300-220 exam
Question #: 10
Topic #: 3
[All 300-220 Questions]

A structured threat hunt using Cisco Secure Network Analytics confirms abnormal internal SMB traffic consistent with lateral movement. Which action should occur NEXT to improve organizational security posture?

Show Suggested Answer Hide Answer
Suggested Answer: C

The correct answer is document findings and create permanent detections. While containment actions are necessary, they are incident response tasks, not threat hunting outcomes.

Cisco's threat hunting lifecycle emphasizes that once malicious behavior is confirmed, teams must:

Document attacker techniques

Identify detection gaps

Convert findings into automated detections

Options A and B are tactical responses that address the current incident but do not prevent recurrence. Option D delays improvement and increases risk.

Operationalizing hunt findings ensures:

Repeated attacker behavior is detected automatically

Future dwell time is reduced

SOC maturity increases

This step directly aligns with the CBRTHD blueprint's focus on continuous improvement and feedback loops between hunting and monitoring.

Therefore, Option C is the correct answer.


Contribute your Thoughts:

0/2000 characters
Isreal
3 days ago
Continuing to monitor seems risky. We need to act fast!
upvoted 0 times
...
Tayna
8 days ago
I feel like documenting findings is crucial for future prevention.
upvoted 0 times
...
Graham
13 days ago
But what about resetting all user credentials? That could help too.
upvoted 0 times
...
Kallie
19 days ago
Agreed, that's the safest option to prevent further damage.
upvoted 0 times
...
Rasheeda
24 days ago
I think we should isolate the affected hosts immediately.
upvoted 0 times
...
Paola
29 days ago
Resetting user credentials might be overkill at this stage.
upvoted 0 times
...
Dortha
1 month ago
Wait, are we sure it’s lateral movement? Sounds suspicious.
upvoted 0 times
...
Barbra
1 month ago
Continuing to monitor seems risky, we need action now!
upvoted 0 times
...
Billy
1 month ago
I think documenting findings is just as important.
upvoted 0 times
...
Kirby
2 months ago
Isolating affected hosts is crucial!
upvoted 0 times
...
Sylvia
2 months ago
Continuing to monitor sounds safe, but I worry that it might let the threat escalate if we wait too long.
upvoted 0 times
...
Ty
2 months ago
I’m leaning towards resetting user credentials, but that seems a bit drastic without more evidence.
upvoted 0 times
...
Princess
2 months ago
I remember a practice question where documenting findings was emphasized, but I feel like we need to act quickly here too.
upvoted 0 times
...
Chauncey
2 months ago
I think isolating the affected hosts is crucial, but I'm not entirely sure if that should be the first step.
upvoted 0 times
...

Save Cancel