CS0-003 · Question #68
Forming a hypothesis, looking for indicators of compromise, and using the findings to proactively improve detection capabilities are examples of the value of:
The correct answer is B. threat hunting. This process of forming hypotheses, searching for indicators of compromise, and improving detection capabilities is characteristic of threat hunting.
Question
Forming a hypothesis, looking for indicators of compromise, and using the findings to proactively improve detection capabilities are examples of the value of:
Options
- Avulnerability scanning.
- Bthreat hunting.
- Cred learning.
- Dpenetration testing.
How the community answered
(16 responses)- A6% (1)
- B88% (14)
- D6% (1)
Why each option
This process of forming hypotheses, searching for indicators of compromise, and improving detection capabilities is characteristic of threat hunting.
Vulnerability scanning is an automated process to identify known weaknesses and misconfigurations in systems, not a proactive process involving hypothesis formation and continuous improvement of detection capabilities.
Threat hunting is a proactive security activity where security professionals actively search for threats within a network that have evaded existing security controls. This process often begins with a hypothesis, involves searching for Indicators of Compromise (IoCs), and uses findings to enhance detection capabilities and overall security posture.
'Red learning' is not a standard, recognized cybersecurity term that describes the activities outlined.
Penetration testing is a simulated cyberattack conducted to identify exploitable vulnerabilities in a system or network, typically focused on known attack vectors rather than actively hunting for unknown or evasive threats and improving general detection.
Concept tested: Threat hunting methodology
Source: https://learn.microsoft.com/en-us/azure/sentinel/hunt-for-threats
Topics
Community Discussion
No community discussion yet for this question.