Your organization subscribes to a commercial threat intelligence feed that provides malicious IP addresses. A new analyst proposes blocking all IPs from the feed at the perimeter firewall immediately. What risk does this approach carry?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because threat intelligence feeds contain entries of varying quality; stale entries (C2 IPs now hosting legitimate content), shared hosting IPs, and CDN ranges can cause legitimate business traffic to be blocked — potentially causing outages. Confidence scoring and validation are essential before automated blocking.
Full explanation below image
Full Explanation
B is correct because threat intelligence feeds contain entries of varying quality; stale entries (C2 IPs now hosting legitimate content), shared hosting IPs, and CDN ranges can cause legitimate business traffic to be blocked — potentially causing outages. Confidence scoring and validation are essential before automated blocking. A is wrong because no threat feed guarantees 100% accuracy or currency. C is wrong because automated firewall blocking does not expose your detection capability to the attacker. D is wrong because blocking an IP address is a network security control, not a GDPR data processing activity.