300-220 · Question #72
When performing a cloud-native threat hunt, which of the following is crucial to analyze?
The correct answer is B. Cloud service configuration settings. Cloud-native threat hunting targets the attack surface that exists within cloud environments, making cloud service configuration settings (B) the critical data source - misconfigurations in IAM policies, storage buckets, security groups, and API gateways are the primary vectors…
Question
When performing a cloud-native threat hunt, which of the following is crucial to analyze?
Options
- APhysical network devices
- BCloud service configuration settings
- COn-premises server logs
- DPrint server logs
How the community answered
(22 responses)- B95% (21)
- C5% (1)
Explanation
Cloud-native threat hunting targets the attack surface that exists within cloud environments, making cloud service configuration settings (B) the critical data source - misconfigurations in IAM policies, storage buckets, security groups, and API gateways are the primary vectors adversaries exploit in cloud attacks. Physical network devices (A) are irrelevant because cloud-native infrastructure is abstracted away from physical hardware that the tenant never controls. On-premises server logs (C) are out of scope for a cloud-native hunt, which by definition focuses on workloads running in the cloud provider's environment. Print server logs (D) are entirely unrelated to cloud infrastructure threats.
Memory tip: Think "cloud-native = cloud config" - when hunting in the cloud, you follow the same logic as any threat hunt (go where the attacker can do damage), and in cloud environments, configuration is the perimeter.
Topics
Community Discussion
No community discussion yet for this question.