During a structured hunt, analysts using Cisco SIEM tools complete hypothesis testing and confirm malicious activity. What is the NEXT step in the Cisco threat hunting lifecycle?
The correct answer is document findings and operationalize detections. In Cisco's threat hunting methodology, confirmation of malicious activity is not the end of the hunt.
The most critical next step is to:
Document attacker behavior
Identify detection gaps
Create or improve SIEM, EDR, or NDR detection rules
This ensures the organization does not repeatedly rediscover the same threat. Options C and D are incident response and communication activities, not threat hunting lifecycle steps. Option A skips the crucial improvement phase.
The CBRTHD blueprint strongly emphasizes:
Continuous improvement
Feedback loops
Detection engineering
By operationalizing findings, the SOC increases maturity and forces adversaries to change tactics.
Therefore, Option B is correct.
Fernanda
1 month agoMollie
2 months agoDarrel
2 months agoViki
2 months agoAileen
2 months agoTruman
2 months agoShala
4 months agoGracie
4 months agoDonette
5 months agoDana
5 months agoDonette
5 months agoDarrin
5 months ago