300-220 · Question #15
Structured threat hunting differs from unstructured threat hunting in that it:
The correct answer is C. Is based on specific hypotheses or indicators. Structured threat hunting is hypothesis-driven, meaning hunters begin with a specific theory or indicator of compromise (IoC) - such as "attackers using this TTPs pattern may have lateral movement in our network" - and systematically search for evidence to confirm or refute it…
Question
Structured threat hunting differs from unstructured threat hunting in that it:
Options
- AIs more ad hoc and relies on the hunter's intuition
- BRequires predefined datasets for analysis
- CIs based on specific hypotheses or indicators
- DDoes not require any prior knowledge of threats
How the community answered
(66 responses)- A5% (3)
- B2% (1)
- C92% (61)
- D2% (1)
Explanation
Structured threat hunting is hypothesis-driven, meaning hunters begin with a specific theory or indicator of compromise (IoC) - such as "attackers using this TTPs pattern may have lateral movement in our network" - and systematically search for evidence to confirm or refute it (C).
Why the distractors are wrong:
- A describes unstructured hunting, which is intuition-based and exploratory rather than methodical.
- B is a distractor because while structured hunting uses data, the defining characteristic is the hypothesis, not a requirement for predefined datasets specifically.
- D is the opposite of reality - structured hunting requires solid threat intelligence and prior knowledge to form valid hypotheses.
Memory tip: Think "Structured = Scientific method" - just as science starts with a hypothesis before gathering evidence, structured threat hunting starts with a hypothesis (or IoC/TTP from frameworks like MITRE ATT&CK) before diving into logs and telemetry.
Topics
Community Discussion
No community discussion yet for this question.