exam questions

Exam CS0-003 All Questions

View all questions & answers for the CS0-003 exam

Exam CS0-003 topic 1 question 119 discussion

Actual exam question from CompTIA's CS0-003
Question #: 119
Topic #: 1
[All CS0-003 Questions]

Which of the following would help an analyst to quickly find out whether the IP address in a SIEM alert is a known-malicious IP address?

  • A. Join an information sharing and analysis center specific to the company's industry
  • B. Upload threat intelligence to the IPS in STIX'TAXII format
  • C. Add data enrichment for IPs in the ingestion pipeline
  • D. Review threat feeds after viewing the SIEM alert
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
FoeMarc
Highly Voted 6 months, 1 week ago
C. Add data enrichment for IPs in the ingestion pipeline. Here's why: Data Enrichment: Data enrichment is the process of adding additional context and information to the data in your SIEM. By enriching the SIEM data with threat intelligence feeds that contain information about known-malicious IP addresses, you can quickly identify whether an IP address in an alert is associated with known threats. This process allows for real-time analysis and correlation of SIEM alerts with known threat indicators.
upvoted 28 times
...
kmordalv
Highly Voted 8 months, 1 week ago
Selected Answer: C
Data enrichment involves enhancing the data in the SIEM system with additional context, such as threat intelligence, before it's processed and analyzed. By adding data enrichment for IPs in the ingestion pipeline, you can check the IP address against threat intelligence feeds, known-malicious IP databases, and other security data sources in real-time. This enables quick identification of whether the IP address is associated with malicious activity.
upvoted 9 times
...
Papaapa77
Most Recent 5 months, 1 week ago
Good job FoeMarc,I like your explanation.
upvoted 5 times
...
Frog_Man
5 months, 2 weeks ago
I select "B" based upon definition and how they are used
upvoted 1 times
Frog_Man
5 months, 2 weeks ago
https://socradar.io/what-you-need-to-know-about-stix-and-taxii/
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago