300-220 · Question #91
When recommending changes to improve threat hunting outcomes, it's important to consider:
The correct answer is A. The potential impact on IT workload and resources. Recommending changes to improve threat hunting must be realistic and operationally sustainable - if changes overwhelm the IT/security team with additional workload or consume resources the organization doesn't have, those recommendations will fail in practice regardless of…
Question
When recommending changes to improve threat hunting outcomes, it's important to consider:
Options
- AThe potential impact on IT workload and resources
- BThe preferences of external auditors
- CThe latest cybersecurity fads
- DReducing the scope of the hunt to minimize effort
How the community answered
(28 responses)- A79% (22)
- B4% (1)
- C4% (1)
- D14% (4)
Explanation
Recommending changes to improve threat hunting must be realistic and operationally sustainable - if changes overwhelm the IT/security team with additional workload or consume resources the organization doesn't have, those recommendations will fail in practice regardless of their technical merit. B is wrong because external auditors' preferences are not the goal of threat hunting; hunts are driven by the organization's risk posture and threat intelligence. C is wrong because chasing cybersecurity trends without evidence-based justification leads to wasted effort and distraction from genuine threats. D is wrong because narrowing the hunt's scope to reduce effort defeats the purpose - threat hunting is proactive and expansive by design; artificially limiting it increases the chance of missing real adversaries.
Memory tip: Think of the word "IMPACT" - before recommending any change, ask "what is the Impact on people, time, and resources?" If a recommendation is operationally viable, it will actually get implemented.
Topics
Community Discussion
No community discussion yet for this question.