An EDR alert shows a workstation making a single 30-second beacon to an unfamiliar external IP. NetFlow confirms the connection, but the payload is not available. You query a threat-intel platform for the IP's reputation, ASN, and recent malware associations. What is the best use of that enrichment when deciding containment?
Select an answer to reveal the explanation.
Short Explanation
Think of threat intel like a neighbor's tip about a suspicious car. It can raise your confidence, but your own cameras still have to show what happened. You enrich the IP to support the local evidence, not to skip straight to containment.
Full Explanation
Threat-intel enrichment adds context to an observed indicator: reputation, ASN, ownership, geolocation, and recent malware associations can raise or lower confidence that a destination is malicious. In containment, local evidence still anchors the decision because the EDR alert, NetFlow pattern, process lineage, and user activity establish that the organization's asset actually communicated. Enrichment supports that chain, helping the analyst decide whether to isolate, block, or continue monitoring. Immediate containment on reputation alone is risky because reputation feeds can be stale, false-positive, or based on unrelated abuse of a hosting provider. Waiting for another beacon before enrichment is also wrong because enrichment is cheap, fast, and can be performed before escalation; the issue is not whether to look it up but how much weight it receives. Replacing local alerting with a feed association is incorrect because an external association does not prove local impact, payload execution, or scope. Exam caveat: choose the answer that treats threat intelligence as corroborating telemetry, not as standalone proof. Operational check: record the IP, enrichment source, timestamp, and confidence in the case, then compare it with EDR process and NetFlow before isolating the host.