QuestionQ57
SOAR Incident Handling and Threat HuntingA partner organization recently experienced a distributed denial-of-service (DDoS) attack, but the adversary’s identity and TTPs are still unknown.
Your SOC has received no relevant threat intelligence from the partner organization, yet you are asked to determine whether comparable activity might be occurring in your environment.
Which threat-hunting action should you take first?
- A Develop a hunting hypothesis based on how DDoS can be executed against your network.
- B Use threat intelligence to enrich the IP addresses of all external source IP addresses.
- C Configure SIEM rules to alert when inbound traffic exceeds baseline thresholds.
- D Use a packet analyzer to capture and review all traffic flows on critical devices.
Community Discussion