Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-220 Exam - Topic 5 Question 2 Discussion

During a structured hunt, analysts using Cisco SIEM tools complete hypothesis testing and confirm malicious activity. What is the NEXT step in the Cisco threat hunting lifecycle?
B) Document findings and operationalize detections
A) Immediately begin a new hypothesis
C) Disable all affected user accounts
D) Escalate the incident directly to executive leadership

Cisco 300-220 Exam - Topic 5 Question 2 Discussion

Actual exam question for Cisco's 300-220 exam
Question #: 2
Topic #: 5
[All 300-220 Questions]

During a structured hunt, analysts using Cisco SIEM tools complete hypothesis testing and confirm malicious activity. What is the NEXT step in the Cisco threat hunting lifecycle?

Show Suggested Answer Hide Answer
Suggested Answer: B

The correct answer is document findings and operationalize detections. In Cisco's threat hunting methodology, confirmation of malicious activity is not the end of the hunt.

The most critical next step is to:

Document attacker behavior

Identify detection gaps

Create or improve SIEM, EDR, or NDR detection rules

This ensures the organization does not repeatedly rediscover the same threat. Options C and D are incident response and communication activities, not threat hunting lifecycle steps. Option A skips the crucial improvement phase.

The CBRTHD blueprint strongly emphasizes:

Continuous improvement

Feedback loops

Detection engineering

By operationalizing findings, the SOC increases maturity and forces adversaries to change tactics.

Therefore, Option B is correct.


Contribute your Thoughts:

0/2000 characters
Fernanda
1 month ago
A is tempting, but we should focus on B first.
upvoted 0 times
...
Mollie
2 months ago
Agreed, B makes sense. We need to operationalize findings.
upvoted 0 times
...
Darrel
2 months ago
I think B is the best choice. Documenting is crucial.
upvoted 0 times
...
Viki
2 months ago
Not sure if escalating to execs is necessary right away...
upvoted 0 times
...
Aileen
2 months ago
Totally agree with B, operationalizing is key!
upvoted 0 times
...
Truman
2 months ago
Wait, disabling all accounts? That seems extreme!
upvoted 0 times
...
Shala
4 months ago
I think A could work too, but not before documenting.
upvoted 0 times
...
Gracie
4 months ago
B is definitely the right move! Document everything.
upvoted 0 times
...
Donette
5 months ago
I’m torn between documenting findings and escalating to leadership. I guess it depends on the severity of the incident, but I lean towards documentation.
upvoted 0 times
...
Dana
5 months ago
I feel like immediately starting a new hypothesis might be too hasty. We should probably focus on what we've already found first, right?
upvoted 0 times
...
Donette
5 months ago
I remember a practice question where we had to decide between documenting findings and escalating an incident. I think documenting is usually the first step after confirming malicious activity.
upvoted 0 times
...
Darrin
5 months ago
I think the next step is to document findings and operationalize detections, but I'm not entirely sure if that's the right order.
upvoted 0 times
...

Save Cancel