nerdexam
CompTIA

SY0-701 · Question #2

A cyber operations team informs a security analyst about a new tactic malicious actors are using to compromise networks. SIEM alerts have not yet been configured. Which of the following best…

The correct answer is D. Threat hunting. Threat hunting is the process of proactively searching for signs of malicious activity or compromise in a network, rather than waiting for alerts or indicators of compromise (IOCs) to appear. Threat hunting can help identify new tactics, techniques, and procedures (TTPs) used…

Submitted by weili_xi· Mar 6, 2026Security Operations

Question

A cyber operations team informs a security analyst about a new tactic malicious actors are using to compromise networks. SIEM alerts have not yet been configured. Which of the following best describes what the security analyst should do to identify this behavior?

Options

  • ADigital forensics
  • BE-discovery
  • CIncident response
  • DThreat hunting

How the community answered

(45 responses)
  • A
    2% (1)
  • B
    4% (2)
  • C
    13% (6)
  • D
    80% (36)

Explanation

Threat hunting is the process of proactively searching for signs of malicious activity or compromise in a network, rather than waiting for alerts or indicators of compromise (IOCs) to appear. Threat hunting can help identify new tactics, techniques, and procedures (TTPs) used by malicious actors, as well as uncover hidden or stealthy threats that may have evaded detection by security tools. Threat hunting requires a combination of skills, tools, and methodologies, such as hypothesis generation, data collection and analysis, threat intelligence, and incident response. Threat hunting can also help improve the security posture of an organization by providing feedback and recommendations for security improvements.

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice