ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 33 - 212-82 discussion

Report
Export

Mark, a security analyst, was tasked with performing threat hunting to detect imminent threats in an organization's network. He generated a hypothesis based on the observations in the initial step and started the threat-hunting process using existing data collected from DNS and proxy logs.

Identify the type of threat-hunting method employed by Mark in the above scenario.

A.
Entity-driven hunting
Answers
A.
Entity-driven hunting
B.
TTP-driven hunting
Answers
B.
TTP-driven hunting
C.
Data-driven hunting
Answers
C.
Data-driven hunting
D.
Hybrid hunting
Answers
D.
Hybrid hunting
Suggested answer: C

Explanation:

A data-driven hunting method is a type of threat hunting method that employs existing data collected from various sources, such as DNS and proxy logs, to generate and test hypotheses about potential threats. This method relies on data analysis and machine learning techniques to identify patterns and anomalies that indicate malicious activity. A data-driven hunting method can help discover unknown or emerging threats that may evade traditional detection methods. An entitydriven hunting method is a type of threat hunting method that focuses on specific entities, such as users, devices, or domains, that are suspected or known to be involved in malicious activity. A TTPdriven hunting method is a type of threat hunting method that leverages threat intelligence and knowledge of adversary tactics, techniques, and procedures (TTPs) to formulate and test hypotheses about potential threats. A hybrid hunting method is a type of threat hunting method that combines different approaches, such as data-driven, entity-driven, and TTP-driven methods, to achieve more comprehensive and effective results.

asked 18/09/2024
Ignacio Negrete
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first