The city SOC matches a quarantined file hash to an Enterprise Security threat list. Unless a blocking control is also in the path, what does that match provide?
Select an answer to reveal the explanation.
Short Explanation
A threat list is a wanted poster, not a locked door. Matching a hash in ES tells you the city has seen that indicator; it does not by itself stop the file unless a control is also in the path. Wanted posters do not tackle people.
Full Explanation
Threat-intelligence platforms and ES threat lists are analysis tools: they enrich events so analysts can ask whether a hash, IP, or domain has been observed. A list match is not a defensive control unless it is paired with something that actually blocks or quarantines, such as EDR, a proxy, or a firewall rule. Presence on a list also does not prove citywide containment or that a SOAR playbook already ran. Treat intel matching as enrichment until a control is confirmed in the path.