🔥 3-day streak
Cisco CCNP Security SCOR (350-701)123 / 146
Question 123 of 146

A threat intelligence analyst at a financial firm has identified several malicious domains and IP addresses during a recent incident investigation that are not yet present in any commercial feed. The analyst wants to create an internal, reusable dataset of these indicators so that the organization's Secure Firewall and Umbrella deployments can automatically block them, and so the dataset can later be shared with an industry ISAC. Which security intelligence activity is the analyst performing when they compile these newly discovered indicators into a structured internal dataset?

Reviewed for accuracy · Report an issueNext question