Loading course title...
Loading assessment title...
Connecting to LMS...
Progress: in progress
Assessment
1. What best describes threat hunting?
A. Running vulnerability scans on a schedule
B. Proactively searching scoped telemetry for adversary activity that may not have alerted
C. Closing compliance checklist items
D. Automatically blocking every unusual event
2. How does hunting differ from alert triage?
A. Hunting begins with an existing alert only
B. Hunting is the same as patch management
C. Hunting ignores evidence and uses intuition
D. Hunting often starts before a clear alert exists
3. What makes a hunt question useful?
A. It is scoped by environment, time window, data source, and expected evidence
B. It asks analysts to search logs randomly
C. It avoids writing down assumptions
D. It requires a vendor-specific tool
4. Which item belongs in a testable hunt hypothesis?
A. A request to scan every host for vulnerabilities
B. A statement that something feels wrong
C. Suspected behavior, required telemetry, expected observations, and decision criteria
D. A final incident report before evidence is reviewed
5. Why should hunters document telemetry gaps?
A. Gaps prove malicious activity occurred
B. Gaps affect what conclusions the hunt can support
C. Gaps make validation unnecessary
D. Gaps replace the need for data sources
6. What is the advantage of hunting for behavior instead of only known indicators?
A. Behavior patterns can remain useful when specific hashes or domains change
B. Behavior hunting removes the need for telemetry
C. Behavior hunting confirms every unusual event is malicious
D. Behavior hunting requires offensive procedures
7. Which pivot is a common hunting move?
A. Changing passwords for every user immediately
B. Deleting all noisy logs
C. Ignoring parent process context
D. Moving from a suspicious process to its parent process and host timeline
8. What is the safest way to reduce noise during a hunt?
A. Delete benign-looking events from the source logs
B. Exclude all administrator activity without review
C. Filter deliberately and document assumptions so signal is not removed accidentally
D. Stop the hunt when the first result appears
9. When should suspicious hunt evidence be escalated to incident response?
A. When it meets the organization's escalation criteria and evidence is preserved
B. Whenever an event is merely uncommon
C. Only after all logs have expired
D. Never, because hunting is separate from response
10. Which outcome is useful even when a hunt finds no compromise?
A. No documentation because nothing happened
B. Improved detection logic, logging, tuned alerts, or documented gaps
C. A claim that compromise is impossible
D. A new exploit procedure
Submit Quiz
Previous