exam questions

Exam SY0-701 All Questions

View all questions & answers for the SY0-701 exam

Exam SY0-701 topic 1 question 24 discussion

Actual exam question from CompTIA's SY0-701
Question #: 24
Topic #: 1
[All SY0-701 Questions]

A cyber operations team informs a security analyst about a new tactic malicious actors are using to compromise networks.
SIEM alerts have not yet been configured. Which of the following best describes what the security analyst should do to identify this behavior?

  • A. Digital forensics
  • B. E-discovery
  • C. Incident response
  • D. Threat hunting
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
metzen227
Highly Voted 11 months, 1 week ago
Threat hunting: Threat hunting involves proactively searching for and identifying potential security threats or indicators of compromise (IOCs) within an organization's network environment. It typically involves the use of advanced analytics, threat intelligence, and specialized tools to detect suspicious behavior or anomalies that may indicate the presence of a threat actor. In the scenario described, where SIEM alerts have not yet been configured to detect the new tactic malicious actors are using, the most appropriate action for the security analyst is Threat hunting. By engaging in threat hunting activities, the security analyst can proactively search for signs of the new tactic within the network environment, helping to identify and mitigate potential security risks before they escalate into full-blown incidents.
upvoted 16 times
...
SHADTECH123
Highly Voted 6 months, 1 week ago
Selected Answer: D
Threat hunting involves proactive searching for signs of compromise or suspicious activities within the network. Since SIEM alerts have not been configured to detect the new tactic, engaging in threat hunting allows the security analyst to actively search for indicators of compromise and emerging threats before they escalate into security incidents.
upvoted 6 times
...
itone333
Most Recent 1 month, 1 week ago
Selected Answer: D
If the SIEM ain't been configured, then you gotta go look for the threat..
upvoted 2 times
...
kai001
6 months, 1 week ago
Selected Answer: D
Threat hunting is a proactive approach used by security analysts to search for signs of malicious activity that might have bypassed existing security measures, such as SIEM alerts. Since the SIEM has not been configured for this new tactic, threat hunting allows the analyst to manually investigate network traffic, logs, endpoints, and other data sources to identify suspicious behavior based on the new information provided by the cyber operations team.
upvoted 1 times
...
dbrowndiver
6 months, 1 week ago
Selected Answer: D
In this scenario, the security analyst needs to proactively search for signs of the new malicious tactic being used in the network, especially since SIEM alerts are not yet configured to detect this behavior. • Scenario Application: Proactive Investigation: With the lack of SIEM alerts, threat hunting allows the analyst to manually search for indicators of the new tactic within network logs, endpoint data, and other security information sources. Adaptability: Threat hunters adapt their techniques based on new intelligence, such as the information provided by the cyber operations team, to identify potential threats that automated systems might miss. Threat hunting is particularly useful when dealing with new or unknown attack tactics that have not yet been incorporated into automated detection systems. By manually analyzing the environment, analysts can identify and understand the behavior of threats, leading to better future alert configurations.
upvoted 2 times
...
hasquaati
11 months ago
Selected Answer: D
Good answer
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago