QuestionQ109

Network Monitoring and Analysis

Mark, a security analyst, was assigned to conduct threat hunting to identify imminent threats in an organization's network. He formed a hypothesis from observations made during the initial step and began the threat-hunting process using existing data gathered from DNS and proxy logs.

Identify the threat-hunting method Mark used in this scenario.

  • A Entity-driven hunting
  • B TTP-driven hunting
  • C Data-driven hunting
  • D Hybrid hunting
Explanation

Data-driven threat hunting starts with available telemetry, such as DNS and proxy logs, and analyzes that data for suspicious patterns or evidence of threats.

Community Discussion

No comments yet. Be the first to start the discussion!