300-220 · Question #131
________ threat hunting is based on the exploration of data with the goal of finding unknown threats.
The correct answer is B. Unstructured. Unstructured threat hunting (B) is correct because it describes an exploratory, open-ended approach where analysts sift through data without a predefined hypothesis, specifically aimed at uncovering previously unknown or unexpected threats. It's driven by curiosity and…
Question
________ threat hunting is based on the exploration of data with the goal of finding unknown threats.
Options
- AStructured
- BUnstructured
- CFormalized
- DHypothesis-driven
How the community answered
(50 responses)- A2% (1)
- B94% (47)
- D4% (2)
Explanation
Unstructured threat hunting (B) is correct because it describes an exploratory, open-ended approach where analysts sift through data without a predefined hypothesis, specifically aimed at uncovering previously unknown or unexpected threats. It's driven by curiosity and intuition rather than a defined path.
- A (Structured) is wrong because structured hunting follows a formal hypothesis - the analyst starts with a specific assumption (e.g., "I believe attackers are using living-off-the-land techniques") and hunts to confirm or deny it.
- C (Formalized) is a distractor with no standard meaning in threat hunting taxonomy; it sounds official but isn't a recognized category.
- D (Hypothesis-driven) is actually a synonym for structured hunting - it describes having a starting theory, the opposite of open exploration.
Memory tip: Think "Unstructured = Unknown" - both start with U. When you don't know what you're looking for, you hunt unstructured-ly through the data. Structured hunting is for when you already have a suspicion to test.
Topics
Community Discussion
No community discussion yet for this question.