nerdexam
Cisco

300-220 · Question #75

The primary use of unstructured threat hunting is to:

The correct answer is B. Explore the network for anomalies without predefined hypotheses. Unstructured threat hunting is an exploratory, open-ended approach where analysts freely investigate network and system data looking for suspicious patterns or anomalies - without starting from a predefined hypothesis or known indicator of compromise. This makes B correct: the…

Threat Hunting Fundamentals

Question

The primary use of unstructured threat hunting is to:

Options

  • AFollow a strict set of rules for analysis
  • BExplore the network for anomalies without predefined hypotheses
  • CConduct compliance audits
  • DDevelop security policies

How the community answered

(42 responses)
  • A
    7% (3)
  • B
    88% (37)
  • C
    2% (1)
  • D
    2% (1)

Explanation

Unstructured threat hunting is an exploratory, open-ended approach where analysts freely investigate network and system data looking for suspicious patterns or anomalies - without starting from a predefined hypothesis or known indicator of compromise. This makes B correct: the defining characteristic of unstructured hunting is that it is not guided by a specific theory upfront, relying instead on analyst intuition and broad observation.

  • A is wrong because following strict rules describes a structured or rule-based approach (like SIEM alerting), not unstructured hunting.
  • C is wrong because compliance audits are a governance activity with a fixed checklist - the opposite of open-ended exploration.
  • D is wrong because policy development is a management/administrative function, unrelated to active threat detection.

Memory tip: Think of unstructured as "no structure = no hypothesis." Just like unstructured data has no predefined format, unstructured threat hunting has no predefined direction - the analyst wanders the environment looking for anything out of the ordinary.

Topics

#Unstructured Threat Hunting#Anomaly Detection#Exploratory Analysis#Hunting Methodologies

Community Discussion

No community discussion yet for this question.

Full 300-220 Practice