nerdexam
Cisco

300-220 · Question #73

What does the Threat Hunting Maturity Model primarily assess in an organization's environment?

The correct answer is B. The organization's capability to actively hunt threats. Option B is correct because the Threat Hunting Maturity Model (THMM), developed by David Bianco, specifically measures how well an organization can proactively search for threats that evade existing security controls - rating teams from Level 0 (initial, relying solely on…

Threat Hunting Fundamentals

Question

What does the Threat Hunting Maturity Model primarily assess in an organization's environment?

Options

  • AThe effectiveness of firewall rules
  • BThe organization's capability to actively hunt threats
  • CThe number of security incidents per year
  • DThe budget allocated to the IT department

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    93% (27)
  • C
    3% (1)

Explanation

Option B is correct because the Threat Hunting Maturity Model (THMM), developed by David Bianco, specifically measures how well an organization can proactively search for threats that evade existing security controls - rating teams from Level 0 (initial, relying solely on automated alerts) up to Level 4 (leading, with advanced analytics and custom data generation). The model is fundamentally about capability and process maturity in active threat hunting, not passive defense measures.

Why the distractors are wrong:

  • A (firewall rules) - Firewall effectiveness is a network security configuration concern, not what maturity models for threat hunting address.
  • C (incidents per year) - Incident count is a metric used in reporting/metrics frameworks, not a capability assessment tool.
  • D (IT budget) - Budget allocation belongs to financial or resource planning frameworks, entirely outside the scope of threat hunting maturity.

Memory tip: Think of the word "maturity" - maturity models always measure capability and process sophistication, not counts, costs, or configurations. If you remember that, you can eliminate A, C, and D immediately on any maturity model question.

Topics

#Threat Hunting Maturity Model#Organizational Capability Assessment#Maturity Levels#Threat Hunting Framework

Community Discussion

No community discussion yet for this question.

Full 300-220 Practice