CompTIA SecurityX (CAS-005)Security OperationsHard

A security team is implementing a new threat hunting program. They want to proactively search for advanced persistent threats (APTs) that may be evading existing security controls. Which of the following approaches would be MOST effective for identifying novel attack techniques and previously unknown indicators of compromise (IOCs) within their environment?

  1. AImplementing a Security Information and Event Management (SIEM) system for log aggregation.
  2. BDeveloping and executing hypothesis-driven hunts based on behavioral analytics and anomaly detection.
  3. CPerforming daily vulnerability scans across all network assets.
  4. DRelying solely on signature-based intrusion detection systems (IDS) alerts.
Show answer & explanation

Correct answer: B. Developing and executing hypothesis-driven hunts based on behavioral analytics and anomaly detection.

Hypothesis-driven threat hunting (C) is the most effective approach for identifying novel attack techniques and unknown IOCs. It involves forming a hypothesis about potential attacker activity, then actively searching for evidence using behavioral analytics and anomaly detection, rather than waiting for alerts or relying on known signatures. While a SIEM (D) is a foundational tool, it doesn't represent the proactive hunting methodology itself.

Why the other options are wrong

  • A. A SIEM is a tool for log aggregation and correlation, but it's the *process* of hypothesis-driven hunting that leverages this data to find unknown threats.
  • C. Vulnerability scans identify weaknesses, but not active, post-exploitation attacker presence or novel techniques.
  • D. Signature-based IDS only detects known threats and will miss novel attack techniques.

Hypothesis-Driven Threat Hunting

A proactive security activity where analysts develop hypotheses about potential malicious activity that might be present in their environment, then actively search for evidence to prove or disprove those hypotheses using various data sources and analytical techniques. It aims to find unknown threats that evade automated defenses.

  • Proactive search for threats.
  • Based on specific hypotheses (e.g., 'An attacker is using X technique').
  • Leverages behavioral analytics and anomaly detection.
  • Aims to find unknown IOCs and novel attack techniques.

Memory trick: Hunt for Threats with Hypotheses, Not Just Alerts.

More Security Operations questions