SPLK-5002 · Question #70
What is the best method to operationalize the results of a threat hunt for daily use by SOC analysts?
The correct answer is C. Create detections based on the documented findings. The best way to operationalize the results of a threat hunt is to create detections based on the documented findings. This transforms hunting insights into actionable, repeatable detection logic that SOC analysts can use daily to identify similar threats in real time.
Question
What is the best method to operationalize the results of a threat hunt for daily use by SOC analysts?
Options
- ACommunicate findings based on the hunt.
- BCreate monthly reports based on the documented findings.
- CCreate detections based on the documented findings.
- DCommunicate gaps to the architecture team.
How the community answered
(50 responses)- A4% (2)
- B14% (7)
- C76% (38)
- D6% (3)
Explanation
The best way to operationalize the results of a threat hunt is to create detections based on the documented findings. This transforms hunting insights into actionable, repeatable detection logic that SOC analysts can use daily to identify similar threats in real time.
Topics
Community Discussion
No community discussion yet for this question.