Quiz 4 Question 7 of 20

A SOC analyst receives an alert for suspicious login attempts from an IP geolocated to a country with no employees. The analyst wants to decide how much weight to give the geolocation data when judging whether the activity is malicious. Which approach best reflects threat-intel hygiene?

Select an answer to reveal the explanation.

Motivation