Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsMedium
A Security Operations Center (SOC) team is faced with a sophisticated, persistent threat actor that has evaded initial detection. The team decides to proactively search for indicators of compromise (IOCs) and TTPs (Tactics, Techniques, and Procedures) that are not yet triggering alerts in their SIEM. What term best describes this proactive security activity?
- AVulnerability Management
- BThreat Hunting
- CSecurity Auditing
- DPenetration Testing
Show answer & explanationAnswer & explanation
Correct answer: B. Threat Hunting
Threat hunting is a proactive security activity where security analysts actively search for threats that have evaded existing security controls and detection systems. This involves looking for IOCs and TTPs that are not yet generating alerts.
Why the other options are wrong
- A. Vulnerability management focuses on identifying and remediating weaknesses in systems, not actively searching for existing threats.
- C. Security auditing is a review of security controls and policies, typically a compliance-focused activity.
- D. Penetration testing is simulating an attack to find vulnerabilities, not actively searching for an existing, unknown compromise.
Threat Hunting
Threat hunting is the proactive and iterative search through networks, endpoints, and datasets to detect and isolate advanced threats that evade existing security solutions.
- Proactive, not reactive.
- Aims to find unknown threats.
- Relies on hypotheses and analyst expertise.
Memory trick: Hunters Seek Unseen Prey.