exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 381 discussion

Actual exam question from CompTIA's CS0-002
Question #: 381
Topic #: 1
[All CS0-002 Questions]

A security operations manager wants to build out an internal threat-hunting capability. Which of the following should be the first priority when creating a threat-hunting program?

  • A. Establishing a hypothesis about which threats are targeting which systems
  • B. Profiling common threat actors and activities to create a list of IOCs
  • C. Ensuring logs are sent to a centralized location with search and filtering capabilities
  • D. Identifying critical assets that will be used to establish targets for threat-hunting activities
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kiduuu
Highly Voted 2 years ago
Selected Answer: C
By aggregating logs in a centralized location with search and filtering capabilities, security analysts can quickly and easily identify anomalous behavior that may indicate a potential threat. Additionally, a centralized location makes it easier to correlate events across multiple systems and identify patterns that may be indicative of an attack.
upvoted 5 times
...
ZUL01
Highly Voted 2 years ago
Selected Answer: D
Source: https://cybersixgill.com/news/articles/4-steps-to-create-an-effective-threat-hunting-roadmap
upvoted 5 times
...
ID77
Most Recent 7 months, 4 weeks ago
Selected Answer: A
According to Jason Dion Course establishing a hypothesis is step 1.
upvoted 1 times
...
SecurityGuyPP
1 year, 6 months ago
Selected Answer: A
You will need to create a hypothesis first before identify anything else. If you go through Jason Dion Course, exabeam article, Trellix/Mcafee article, or even SANS article, it will tell you that hypothesis will be the first step for threat hunting. Look it up.
upvoted 3 times
...
grelaman
1 year, 7 months ago
Selected Answer: A
All Books/authors are saying that the first step in every threat hunting process is to Stablish an hypotesis. The hypothesis serves as a foundational element that helps guide the investigation by formulating a specific assumption or theory about a potential threat.
upvoted 4 times
...
kumax
1 year, 7 months ago
Selected Answer: D
ChatGPT: When creating a threat-hunting program, the first priority should be to establish a clear and well-defined threat-hunting strategy. This strategy should serve as the foundation for all threat-hunting activities and guide the development of the program. Here are key steps and considerations for building an effective threat-hunting program: Define Objectives and Scope: Clearly define the goals and objectives of your threat-hunting program. Determine the scope of the program, including the systems, networks, and data you intend to protect.
upvoted 1 times
...
rg00
1 year, 8 months ago
Proactive threat hunting always start in establishing a hypothesis. Source: Jason Dion and Mike Chapple CySA Study Guides
upvoted 2 times
...
rg00
1 year, 8 months ago
Selected Answer: A
Proactive threat hunting always start in establishing a hypothesis. Source: Jason Dion and Mike Chapple CySA Study Guides
upvoted 3 times
...
Dutch012
1 year, 11 months ago
I think D works better with risk assessment, so it is not D. A could be the right answer because Threat hunting is a proactive approach to look for IOC so it starts with hypotheses or anomaly logs helper source: https://www.crowdstrike.com/cybersecurity-101/threat-hunting/
upvoted 2 times
...
NerdAlert
1 year, 11 months ago
Selected Answer: D
I vote D, even moreso after reading the link Zulu put. Gotta identify what you want to threat hunt instead of wasting time analyzing everything all at once
upvoted 2 times
...
CyberCEH
2 years ago
Answer C
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...