300-220 Exam Questions
140 real 300-220 exam questions with expert-verified answers and explanations. Page 1 of 3.
- Question #1Threat Hunting Processes
What is the first step in determining attack tactics, techniques, and procedures using logs?
Log CorrelationThreat Hunting ProcessEvent AnalysisAttack Investigation - Question #2Threat Hunting Fundamentals
Memory-resident malware detection is challenging because:
Memory-resident malwareMalware detectionDetection evasionDisk artifacts - Question #3Threat Modeling Techniques
IoT device threat analysis must include: (Choose two)
IoT threat analysisOS security assessmentapplication behavior analysisdevice threat modeling - Question #4Threat Hunting Outcomes
Effective use of presentation resources to convey findings involves:
Presentation SkillsAudience AnalysisStakeholder CommunicationFindings Reporting - Question #5Threat Hunting Fundamentals
The integration of which products would most enhance analytical capabilities for threat hunting?
SIEMEDRThreat IntelligenceTool Integration - Question #6Threat Hunting Techniques
What is a key advantage of AI in cybersecurity?
AI/ML in securitythreat detectiondata analysissecurity capabilities - Question #7Threat Hunting Processes
How does TaHiTI contribute to cybersecurity practices?
TaHiTI frameworkThreat huntingIncident responseCybersecurity processes - Question #8Threat Hunting Techniques
Reverse engineering is used to determine compromises by:
Reverse EngineeringMalware AnalysisCode DisassemblyIncident Response - Question #9Threat Hunting Processes
To improve hunt capability and mature in the Threat Hunting Maturity Model, an organization should first:
Threat Hunting Maturity ModelStandard Operating ProceduresProcess FoundationOrganizational Development - Question #10Threat Hunting Processes
A runbook or playbook for a detectable scenario should include:
Incident Response PlaybookContainment and RecoveryThreat Detection ResponseRunbook Development - Question #11Threat Hunting Techniques
Identifying memory-resident attacks often requires the use of:
Memory forensicsMalware analysisMemory-resident malwareForensic tools - Question #12Threat Modeling Techniques
The Cyber Kill Chain helps in determining the priority level of attacks by:
Cyber Kill ChainAttack FrameworkAttack StagesThreat Modeling - Question #13Threat Hunting Processes
Attack remediation strategies should be based on:
threat assessmentattack remediationrisk-based strategyincident response - Question #14Threat Hunting Fundamentals
Effective tools and configurations for detection should:
detection toolspatch managementsecurity updatesconfiguration management - Question #15Threat Hunting Fundamentals
Structured threat hunting differs from unstructured threat hunting in that it:
Structured threat huntingThreat hunting methodologyHypotheses-driven analysisThreat intelligence - Question #16Threat Hunting Techniques
A mitigation strategy for blocking C2 traffic that involves analyzing behavioral patterns is known as:
C2 Traffic DetectionAnomaly-Based DetectionBehavioral AnalysisNetwork Monitoring - Question #17Threat Hunting Fundamentals
Endpoint artifacts are crucial for uncovering undetected threats. Which of the following are considered endpoint artifacts? (Choose two)
Endpoint artifactsWindows RegistryLinux Bash historyArtifact classification - Question #18Threat Hunting Fundamentals
A delivery method that is commonly used by threat actors but rarely in authorized assessments is:
zero-day vulnerabilitiesthreat actor tacticsauthorized assessmentsvulnerability exploitation - Question #19Threat Modeling Techniques
Selecting the appropriate threat modeling approach for a scenario requires understanding the:
threat modelingsecurity requirementsassessment contextmethodology selection - Question #20Threat Hunting Techniques
Selecting deception techniques for a scenario involves:
Deception TechniquesHoneypotsNetwork DefenseThreat Detection - Question #21Threat Hunting Techniques
When interpreting data from memory-specific tools, what is crucial to identify?
memory forensicsanomaly detectionexploitation indicatorsthreat hunting - Question #22Threat Hunting Processes
Identifying analytical gaps using threat hunting methodologies helps in:
Analytical GapsProcess ImprovementThreat Hunting MethodologiesGap Analysis - Question #23Threat Hunting Fundamentals
To identify unknown gaps in detection, one should:
detection gapssecurity assessmentsvulnerability identificationproactive defense - Question #24Threat Actor Attribution Techniques
A tactic that indicates a sophisticated threat actor rather than a commodity malware campaign is:
threat actor classificationtargeted attacksspear-phishingAPT indicators - Question #25Threat Hunting Techniques
In cloud-native threat hunting, which AWS service's logs are essential for analysis?
AWS CloudTrailCloud LoggingThreat HuntingCloud Forensics - Question #26Threat Hunting Techniques
What indicates a successful C2 communication detection using endpoint logs? (Choose two)
C2 DetectionEndpoint LogsProcess Tree AnalysisNetwork Indicators - Question #27Threat Actor Attribution Techniques
Artifacts at which level of the Pyramid of Pain provide the most context about an attack but are also the most challenging to use for attribution?
Pyramid of PainTTPsAttributionThreat Intelligence - Question #28Threat Actor Attribution Techniques
To attribute a cyber attack to a specific threat actor, analysts primarily look for:
TTPsAttributionActor ProfilingBehavioral Analysis - Question #29Threat Hunting Outcomes
Advancing in the Threat Hunting Maturity Model involves:
Threat Hunting MaturityIntegrationSecurity OperationsFindings Application - Question #30Threat Actor Attribution Techniques
What aspect of a threat intelligence report is critical in drawing conclusions about threat actor tactics?
threat-intelligencevulnerability-analysisthreat-actor-tacticsttp-assessment - Question #31Threat Hunting Techniques
To determine C2 communications from infected hosts, analysts should examine:
C2 CommunicationsNetwork Traffic AnalysisEncrypted Traffic PatternsThreat Hunting - Question #32Threat Hunting Techniques
How can logs help in identifying the tactics, techniques, and procedures of a threat actor?
log analysisthreat actor TTPsanomaly detectionthreat behavior patterns - Question #33Threat Hunting Fundamentals
What does the Pyramid of Pain illustrate?
Pyramid of PainIndicators of CompromiseThreat IntelligenceIOC Prioritization - Question #34Threat Hunting Outcomes
Effective communication of threat hunting findings should:
Audience tailoringFindings communicationStakeholder engagementTechnical communication - Question #35Threat Hunting Processes
Recommending changes to improve threat hunt efficiency can include: (Choose two)
Signal-to-noise ratioAlert tuningCommunication efficiencyThreat hunting optimization - Question #36Threat Hunting Fundamentals
Threat intelligence handling involves all of the following EXCEPT:
Threat IntelligenceData GatheringIntelligence CatalogingDefensive Operations - Question #37Threat Hunting Fundamentals
Security countermeasures should:
defense-in-depthlayered-securitysecurity-countermeasuresperimeter-security - Question #38Threat Hunting Processes
To advance to the next phase of the Threat Hunting Maturity Model, an organization should:
Maturity ModelsTool IntegrationCollaborationProcess Evolution - Question #39Threat Hunting Processes
A recommended change to enhance detection methodology includes: (Choose two)
Incident Response PlanningData Collection & NormalizationDetection MethodologySecurity Operations - Question #40Threat Hunting Processes
When constructing a runbook, it is essential to include:
RunbooksIncident ResponseContact InformationDocumentation - Question #41Threat Hunting Processes
Multiproduct integration accelerates analysis by:
multiproduct integrationautomated responseSOARalert acceleration - Question #42Threat Hunting Fundamentals
The primary goal of using BURP Suite in code-level analysis is to:
BURP SuiteWeb vulnerability assessmentPenetration testingApplication security - Question #43Threat Modeling Techniques
The MITRE ATT&CK framework is primarily used for modeling:
MITRE ATT&CKThreat ModelingTTPsAttack Framework - Question #44Threat Hunting Fundamentals
________ involves proactively searching through networks to detect and isolate advanced threats that evade existing security solutions.
Threat HuntingProactive DetectionAdvanced ThreatsNetwork Security - Question #45Threat Modeling Techniques
When using the MITRE ATT&CK framework to model threats, changes in ________ are critical for understanding evolving attack strategies.
MITRE ATT&CKTTPsThreat ModelingAttack Strategies - Question #46Threat Hunting Processes
Utilizing threat intelligence effectively means integrating it into ________ processes.
Threat IntelligenceDefensive SecurityProcess IntegrationThreat Hunting - Question #47Threat Hunting Fundamentals
Procedures of a given threat actor can include:
threat actor proceduresTTPsantivirus evasionthreat attribution - Question #48Threat Modeling Techniques
The likelihood of an attack in a given environment can be recognized by:
attack vectorsthreat likelihoodhistorical patternsrisk indicators - Question #49Threat Hunting Techniques
When analyzing IoT devices, which aspect is critical?
IoT analysisnetwork behaviorthreat detectiondevice reconnaissance - Question #50Threat Hunting Fundamentals
Selecting suspicious activity often involves analyzing session and protocol data. Which protocol is commonly scrutinized for this purpose?
protocol analysissession datanetwork traffic analysissuspicious activity detection