CompTIA Security+ (SY0-701)Security OperationsMedium
A SOC has fully deployed automated alerting and EDR tools, yet a security analyst proactively formulates a hypothesis that an APT group may already be present in the network and begins manually searching endpoint and network logs for subtle indicators that automated tools missed. Which activity is the analyst performing?
- AIncident response triage
- BPenetration testing
- CThreat hunting
- DVulnerability scanning
Show answer & explanationAnswer & explanation
Correct answer: C. Threat hunting
Threat hunting is a proactive, hypothesis-driven search for threats that have evaded existing automated detection controls, as opposed to reactive alert handling.
Why the other options are wrong
- A. Incident response triage reacts to a confirmed alert, not proactive undetected threat searching.
- B. Penetration testing simulates attacks to test defenses, not search for existing intrusions.
- D. Vulnerability scanning identifies weaknesses, not active compromise indicators.
Threat Hunting
A proactive, analyst-driven process of searching networks and endpoints for signs of compromise that automated tools have not detected.
- Starts with a hypothesis based on threat intelligence or TTPs
- Uses log analysis, EDR data, and behavioral baselines
- Differs from incident response, which reacts to known alerts
Memory trick: The hunter stalks silently before the alarm ever rings.