nerdexam
Cisco

300-220 · Question #72

When performing a cloud-native threat hunt, which of the following is crucial to analyze?

The correct answer is B. Cloud service configuration settings. Cloud-native threat hunting targets the attack surface that exists within cloud environments, making cloud service configuration settings (B) the critical data source - misconfigurations in IAM policies, storage buckets, security groups, and API gateways are the primary vectors…

Threat Hunting Fundamentals

Question

When performing a cloud-native threat hunt, which of the following is crucial to analyze?

Options

  • APhysical network devices
  • BCloud service configuration settings
  • COn-premises server logs
  • DPrint server logs

How the community answered

(22 responses)
  • B
    95% (21)
  • C
    5% (1)

Explanation

Cloud-native threat hunting targets the attack surface that exists within cloud environments, making cloud service configuration settings (B) the critical data source - misconfigurations in IAM policies, storage buckets, security groups, and API gateways are the primary vectors adversaries exploit in cloud attacks. Physical network devices (A) are irrelevant because cloud-native infrastructure is abstracted away from physical hardware that the tenant never controls. On-premises server logs (C) are out of scope for a cloud-native hunt, which by definition focuses on workloads running in the cloud provider's environment. Print server logs (D) are entirely unrelated to cloud infrastructure threats.

Memory tip: Think "cloud-native = cloud config" - when hunting in the cloud, you follow the same logic as any threat hunt (go where the attacker can do damage), and in cloud environments, configuration is the perimeter.

Topics

#cloud-native threat hunting#cloud configuration analysis#threat hunting scope#cloud security focus

Community Discussion

No community discussion yet for this question.

Full 300-220 Practice