A SOC analyst receives an alert for suspicious login attempts from an IP geolocated to a country with no employees. The analyst wants to decide how much weight to give the geolocation data when judging whether the activity is malicious. Which approach best reflects threat-intel hygiene?
Select an answer to reveal the explanation.
Short Explanation
Think of geolocation like a blurry license-plate photo: it might point you down a street, but it won't prove who parked there. You shouldn't lock the gate just because the plate came from a strange town. Use it as a hint, then chase the stronger evidence in logs, intel, and behavior.
Full Explanation
Geolocation places an IP address in a broad physical or network region, but that placement is frequently wrong because public IP ownership, routing, NAT, cloud egress, proxies, VPNs, and compromised hosts can make traffic appear to originate from a location unrelated to the adversary. In threat hunting, geolocation should be used as low-confidence enrichment that supports or weakens a hypothesis only when corroborated by telemetry, indicators, and behavior. Blocking solely because a country is unusual creates false positives and can interrupt legitimate business traffic. Correlating location with attacker infrastructure is still weak if the only input is geolocation, because infrastructure confidence comes from ASN, hosting provider, certificate reuse, DNS history, and prior C2 patterns rather than latitude and longitude. Treating location as primary attribution evidence is especially risky because attribution requires repeated, independent evidence and is rarely justified by a single IP lookup. Exam caveat: CS0-004 expects analysts to interpret indicators with confidence levels, not to let one enrichment field drive containment. Operational check: Before escalating an alert, compare the geolocation result with user-agent, authentication source, EDR process lineage, and whether the ASN belongs to a known VPN or cloud provider.