A cyber operations team informs a security analyst about a new tactic malicious actors are using to compromise networks. SIEM alerts have not yet been configured. Which of the following best describes what the security analyst should do to identify this behavior?
Choose an answer
Tap an option to check your answer.
Correct answer: Threat hunting.
Why this is the answer
Threat hunting is the proactive search for cyber threats that are evading existing security solutions. Since the team is aware of a new tactic and SIEM alerts aren't yet configured, the analyst needs to actively search for indicators of this new behavior within the network. Digital forensics is typically a post-incident activity to investigate a breach. E-discovery is related to legal processes for finding electronic data. Incident response is the process of reacting to and managing a security incident that has already been detected.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed