exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 421 discussion

Actual exam question from CompTIA's CS0-002
Question #: 421
Topic #: 1
[All CS0-002 Questions]

Which of the following are important reasons for performing proactive threat-hunting activities? (Choose two.)

  • A. To ensure all alerts are fully investigated
  • B. To test incident response capabilities
  • C. To uncover unknown threats
  • D. To allow alerting rules to be more specific
  • E. To create a new security baseline
  • F. To improve user awareness about security threats
Show Suggested Answer Hide Answer
Suggested Answer: CE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
skibby16
1 year, 7 months ago
Selected Answer: CE
o uncover unknown threats that may have evaded detection by existing security tools or controls, and to mitigate them before they cause damage or data loss. To create a new security baseline that reflects the current state of the network, and to identify any anomalies or deviations from the normal behavior or activity.
upvoted 2 times
...
grelaman
1 year, 8 months ago
Selected Answer: CE
C. To uncover unknown threats By definition, Threat hunting is the process of actively searching for threats that may be lurking in a network or environment, undetected by traditional security controls E. To create a new security baseline A security baseline is a set of security controls that are considered to be the minimum necessary to protect an information system or asset. It is a starting point for improving the security of an organization, and it can be used to assess the current security posture of an organization and identify areas where improvement is needed. In the official book of comptia is described as one of the benefits of threat hunting as an opportunity to redesign systems, controls, configuration, data protection, etc. to reduce the overall attack surface.
upvoted 3 times
grelaman
1 year, 8 months ago
Why not D? I think that optimizing rules is part of a broader concept which is create a new security baseline what covers all the new security posture aspects of the organization that the threat hunting process discovered.
upvoted 2 times
[Removed]
1 year, 7 months ago
Agree with your analysis. Essentially, D would be part of E.
upvoted 1 times
...
...
...
skibby16
1 year, 8 months ago
Selected Answer: CF
C. To uncover unknown threats: Threat hunting involves actively seeking out security threats and anomalies that may not have triggered traditional security alerts. This proactive approach helps identify threats that might otherwise go undetected. F. To improve user awareness about security threats: By conducting threat-hunting activities and sharing the findings with users and employees, organizations can raise awareness about security threats and encourage a culture of cybersecurity awareness among their staff. This helps users become more vigilant and security-conscious, reducing the likelihood of falling victim to threats.
upvoted 1 times
...
Saphi
1 year, 9 months ago
Selected Answer: CD
Amazingly I actually agree with the provided answer for a change. C and D
upvoted 1 times
...
Dree_Dogg
1 year, 9 months ago
Selected Answer: CD
C, D. Yeah, they seem to be the only ones that make sense here.
upvoted 2 times
...
Abz1999
1 year, 9 months ago
Selected Answer: AD
A and D as they are mentioned in the definition below: Threat hunting is the practice of proactively searching for cyber threats that are lurking undetected in a network. Cyber threat hunting digs deep to find malicious actors in your environment that have slipped past your initial endpoint security defenses
upvoted 1 times
Abz1999
1 year, 9 months ago
Moderator, please remove my vote, as I meant C AND D
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...