Cisco CCNP Security Core (SCOR) 350-701Security ConceptsMedium
A security operations center (SOC) receives an alert indicating unusually high outbound network traffic from an internal server, destined for an unknown external IP address. Further investigation reveals that the server is communicating with a known command-and-control (C2) server associated with a specific malware family. This information about the C2 server and malware family is an example of:
- AThreat Intelligence
- BSecurity Policy
- CSecurity Awareness Training
- DSecurity Framework
Show answer & explanationAnswer & explanation
Correct answer: A. Threat Intelligence
Information about known command-and-control (C2) servers and specific malware families constitutes threat intelligence. This intelligence provides context and actionable insights into threats, enabling better detection and response.
Why the other options are wrong
- B. A security policy is a set of rules, not information about specific threats.
- C. Security awareness training educates users, not provides real-time threat data to a SOC.
- D. A security framework is a structured approach to managing security, not specific threat data.
Threat Intelligence
Organized, analyzed, and refined information about potential or actual threats that can be used to mitigate risks and make informed security decisions.
- Includes Indicators of Compromise (IOCs) like C2 IP addresses.
- Provides context about threat actors, motives, and methods.
- Used to enhance detection, prevention, and response capabilities.
Memory trick: Concepts are the 'CON'crete 'CEP'ts of 'SECURITY' 'THOUGHT'.