nerdexam
Cisco

300-220 · Question #15

Structured threat hunting differs from unstructured threat hunting in that it:

The correct answer is C. Is based on specific hypotheses or indicators. Structured threat hunting is hypothesis-driven, meaning hunters begin with a specific theory or indicator of compromise (IoC) - such as "attackers using this TTPs pattern may have lateral movement in our network" - and systematically search for evidence to confirm or refute it…

Threat Hunting Fundamentals

Question

Structured threat hunting differs from unstructured threat hunting in that it:

Options

  • AIs more ad hoc and relies on the hunter's intuition
  • BRequires predefined datasets for analysis
  • CIs based on specific hypotheses or indicators
  • DDoes not require any prior knowledge of threats

How the community answered

(66 responses)
  • A
    5% (3)
  • B
    2% (1)
  • C
    92% (61)
  • D
    2% (1)

Explanation

Structured threat hunting is hypothesis-driven, meaning hunters begin with a specific theory or indicator of compromise (IoC) - such as "attackers using this TTPs pattern may have lateral movement in our network" - and systematically search for evidence to confirm or refute it (C).

Why the distractors are wrong:

  • A describes unstructured hunting, which is intuition-based and exploratory rather than methodical.
  • B is a distractor because while structured hunting uses data, the defining characteristic is the hypothesis, not a requirement for predefined datasets specifically.
  • D is the opposite of reality - structured hunting requires solid threat intelligence and prior knowledge to form valid hypotheses.

Memory tip: Think "Structured = Scientific method" - just as science starts with a hypothesis before gathering evidence, structured threat hunting starts with a hypothesis (or IoC/TTP from frameworks like MITRE ATT&CK) before diving into logs and telemetry.

Topics

#Structured threat hunting#Threat hunting methodology#Hypotheses-driven analysis#Threat intelligence

Community Discussion

No community discussion yet for this question.

Full 300-220 Practice