QuestionQ28

Threat Hunting Processes

Refer to the exhibit.

Question Image

An organization engages a Breach and Attack Simulation vendor to measure response readiness and identify threat-detection coverage gaps within its SOC capability. The organization also uses the TaHiTI Magma Threat Hunting methodology and its Use Case Framework for the case-management lifecycle and to define detection technology and log sources across the organization. The organization must keep threat-detection coverage current.

Which gaps would an analyst diagnose from the exhibit?

Explanation

Command & Control has substantially deficient detection readiness: effectiveness is 21%, and both implementation and coverage are 15%, whereas the other active use cases are at 95%. This identifies a Command & Control detection-tooling and telemetry gap. Implementing NetFlow, SIEM, and DLP/AMP capabilities supplies the network-flow, centralized detection, and data-protection visibility needed to improve Command & Control detection coverage.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!