300-220 · Question #102
During the investigation phase of the threat hunting process, what activity is typically conducted?
The correct answer is B. Collecting additional data. During the investigation phase of threat hunting, analysts collect additional data (B) to validate or refute the hypothesis formed earlier. This phase involves deep-diving into logs, network traffic, endpoint telemetry, and other data sources to understand the scope and nature…
Question
During the investigation phase of the threat hunting process, what activity is typically conducted?
Options
- ARefining hypotheses
- BCollecting additional data
- CGenerating threat intelligence reports
- DMitigating the threat
How the community answered
(27 responses)- A7% (2)
- B89% (24)
- D4% (1)
Explanation
During the investigation phase of threat hunting, analysts collect additional data (B) to validate or refute the hypothesis formed earlier. This phase involves deep-diving into logs, network traffic, endpoint telemetry, and other data sources to understand the scope and nature of a potential threat.
Why the distractors are wrong:
- A (Refining hypotheses) happens in the hypothesis phase, which precedes investigation - you form and refine your idea of what threat to look for before you start digging.
- C (Generating threat intelligence reports) is a post-hunt activity that occurs after findings are documented, not during active investigation.
- D (Mitigating the threat) belongs to the response/remediation phase - you don't mitigate until you've confirmed a threat exists through investigation.
Memory tip: Think of threat hunting like a detective case - you form a theory (hypothesis), then collect evidence (investigation), then write the case report (intel reporting), then make an arrest (mitigation). The investigation phase is always about gathering, not acting.
Topics
Community Discussion
No community discussion yet for this question.