QuestionQ109
Network Monitoring and AnalysisMark, a security analyst, was assigned to conduct threat hunting to identify imminent threats in an organization's network. He formed a hypothesis from observations made during the initial step and began the threat-hunting process using existing data gathered from DNS and proxy logs.
Identify the threat-hunting method Mark used in this scenario.
- A Entity-driven hunting
- B TTP-driven hunting
- C Data-driven hunting
- D Hybrid hunting
Community Discussion