Unit 6: Advanced Threat Hunting and Future Trends - Practice Quiz

INT244 — Securing Computing Systems 60 Questions
0 Correct 0 Wrong 60 Left
0/60

1 What is threat intelligence?

Threat Intelligence and Advanced Threat Hunting: introduction Easy
A. A tool for increasing network speed
B. A backup of critical business data
C. Analyzed information about cyber threats
D. A policy for purchasing computer hardware

2 What is the main purpose of threat hunting?

Threat Intelligence and Advanced Threat Hunting: introduction Easy
A. To create backups of security logs
B. To proactively search for hidden threats
C. To replace all network security controls
D. To improve the speed of applications

3 What usually begins a hypothesis-driven threat hunt?

Threat Intelligence and Advanced Threat Hunting: advanced threat-hunting methodologies Easy
A. A complete shutdown of every monitored system until the investigation has ended
B. A request to upgrade computer hardware
C. A testable idea about suspicious activity
D. A plan to remove all existing security policies

4 Which item is an example of an indicator of compromise (IOC)?

Threat Intelligence and Advanced Threat Hunting: advanced threat-hunting methodologies Easy
A. A known malicious IP address
B. A standard software license agreement
C. A scheduled employee training session
D. A newly purchased office printer

5 Which activity is part of the threat intelligence lifecycle?

Threat Intelligence and Advanced Threat Hunting: lifecycle intelligence for automated response Easy
A. Increasing monitor brightness
B. Designing a company logo
C. Ordering replacement keyboards
D. Collecting relevant threat data

6 How can threat intelligence support an automated response?

Threat Intelligence and Advanced Threat Hunting: lifecycle intelligence for automated response Easy
A. By physically repairing damaged computers
B. By triggering actions from known indicators
C. By automatically writing every company policy
D. By eliminating the need for security monitoring

7 Which data source is especially useful for cloud threat hunting?

Threat Intelligence and Advanced Threat Hunting: techniques for effective threat hunting in the cloud Easy
A. Employee cafeteria order records
B. Cloud audit and activity logs
C. Office building maintenance reports
D. Printed equipment instruction manuals

8 Why should cloud threat hunters monitor identity activity?

Threat Intelligence and Advanced Threat Hunting: techniques for effective threat hunting in the cloud Easy
A. To ensure every employee uses the same device model and operating system version
B. To measure the physical temperature of servers
C. To detect compromised user accounts
D. To calculate the cost of office furniture

9 What does behavioral analytics commonly establish for each user?

Threat Intelligence and Advanced Threat Hunting: behavioral analytics for detecting insider threats Easy
A. A schedule of hardware purchases
B. A baseline of normal activity
C. A map of office seating locations
D. A list of preferred software colors

10 Which behavior could indicate a possible insider threat?

Threat Intelligence and Advanced Threat Hunting: behavioral analytics for detecting insider threats Easy
A. Downloading unusually large amounts of data
B. Installing an approved operating system update
C. Using a company-approved collaboration tool
D. Attending a scheduled security awareness course

11 What is the main role of a Security Operations Center (SOC)?

Emerging Trends and the Future of SOC Analysis: introduction Easy
A. Designing physical office spaces
B. Monitoring and responding to security threats
C. Managing product advertising and sales
D. Processing employee travel expenses

12 Who typically investigates security alerts in a SOC?

Emerging Trends and the Future of SOC Analysis: introduction Easy
A. Building architects
B. Sales representatives
C. SOC analysts
D. Graphic designers

13 Which technology is increasingly used to identify patterns in large volumes of SOC data?

Emerging Trends and the Future of SOC Analysis: emerging trends and the future of SOC analysis Easy
A. Analog photography
B. A manual process that permanently replaces every security tool and analyst in the SOC
C. Machine learning
D. Mechanical printing

14 How does cloud computing affect SOC monitoring?

Emerging Trends and the Future of SOC Analysis: impact of cloud security on SOC operations Easy
A. It prevents the collection of security logs
B. It removes the need to monitor identities
C. It limits incidents to physical servers
D. It expands monitoring beyond local networks

15 Which characteristic can make cloud assets harder for a SOC to track?

Emerging Trends and the Future of SOC Analysis: impact of cloud security on SOC operations Easy
A. Their complete lack of user identities
B. Their inability to generate activity logs
C. Their permanent physical location
D. Their rapid and temporary creation

16 Which capability is likely to become more important in future SOC operations?

Emerging Trends and the Future of SOC Analysis: predicting future directions Easy
A. Replacing digital logs with paper records
B. Disabling all sources of security alerts
C. Automating repetitive investigation tasks
D. Avoiding integration between security tools

17 Why do SOC analysts need continuous training?

Emerging Trends and the Future of SOC Analysis: predicting future directions Easy
A. Cyberattacks always use one technique
B. Security tools never receive updates
C. Threats and technologies keep changing
D. Cloud services eliminate security risks

18 What does SOAR stand for in cybersecurity?

Emerging Trends and the Future of SOC Analysis: SOAR Easy
A. System Optimization, Auditing, and Recovery
B. Security Orchestration, Automation, and Response
C. Software Organization and Automated Resource Management for Every Department
D. Security Operations, Assessment, and Reporting

19 What is a SOAR playbook?

Emerging Trends and the Future of SOC Analysis: SOAR Easy
A. A guide for assembling computer hardware
B. A record of monthly software expenses
C. A predefined incident-response workflow
D. A list of employee contact details

20 Which statement best represents the zero-trust security model?

Emerging Trends and the Future of SOC Analysis: zero-trust security model Easy
A. Verify devices only during initial setup
B. Never trust automatically; always verify
C. Allow broad access after one login
D. Trust every user inside the network

21 A SOC receives a list of malicious IP addresses from an industry-sharing group. What should analysts do first before blocking every address?

Threat Intelligence and Advanced Threat Hunting: introduction Medium
A. Validate the indicators against internal telemetry and business context
B. Replace existing detection rules with the shared indicator list
C. Delete historical events associated with the listed indicators
D. Block the indicators immediately across all security controls

22 Which activity best distinguishes proactive threat hunting from routine alert monitoring?

Threat Intelligence and Advanced Threat Hunting: introduction Medium
A. Investigating hypotheses even when no alert has been generated
B. Escalating confirmed incidents to the response team
C. Reviewing alerts according to their assigned severity levels
D. Closing duplicate alerts generated by multiple security tools

23 A hunter suspects that attackers are using PowerShell to download payloads. Which hypothesis-driven approach is most appropriate?

Threat Intelligence and Advanced Threat Hunting: advanced threat-hunting methodologies Medium
A. Scan all servers only for known malicious file hashes
B. Disable PowerShell immediately on every managed endpoint
C. Search process and network logs for unusual PowerShell connections
D. Review firewall configuration changes from the previous year

24 During a hunt mapped to the MITRE ATT&CK framework, analysts find repeated attempts to dump credentials from endpoint memory. How should this finding primarily be used?

Threat Intelligence and Advanced Threat Hunting: advanced threat-hunting methodologies Medium
A. Remove unrelated endpoint events from the investigation
B. Map the activity to a technique and search for related behaviors
C. Treat the activity as harmless unless malware is recovered
D. Assign the activity directly to a specific threat group

25 A phishing indicator has moved from newly observed to confirmed malicious during the intelligence lifecycle. Which automated response is most appropriate?

Threat Intelligence and Advanced Threat Hunting: lifecycle intelligence for automated response Medium
A. Block the indicator and search historical telemetry for matches
B. Isolate every endpoint regardless of indicator exposure
C. Delete all messages received during the same time period
D. Archive the indicator without changing security controls

26 Why should an automated response workflow assign expiration times to threat indicators?

Threat Intelligence and Advanced Threat Hunting: lifecycle intelligence for automated response Medium
A. To ensure indicators remain blocked after they become irrelevant
B. To remove the need for confidence scoring and validation
C. To prevent outdated indicators from causing unnecessary disruption
D. To make all intelligence sources equally trusted over time

27 An attacker creates a new cloud access key and uses it from an unfamiliar country. Which data combination is most useful for investigating the event?

Threat Intelligence and Advanced Threat Hunting: techniques for effective threat hunting in the cloud Medium
A. Printer logs, endpoint wallpaper, and asset purchase dates
B. Backup schedules, software licenses, and office locations
C. Cloud audit logs, identity events, and geolocation data
D. Application screenshots, source code, and DNS zone names

28 A cloud workload is short-lived and may disappear before an investigation begins. Which practice best preserves evidence for threat hunting?

Threat Intelligence and Advanced Threat Hunting: techniques for effective threat hunting in the cloud Medium
A. Centralize workload, control-plane, and network logs continuously
B. Store each workload's logs only on its local file system
C. Collect logs manually only after an incident is confirmed
D. Disable autoscaling until analysts complete every investigation

29 An employee who normally accesses a few customer records downloads thousands shortly before resigning. Which detection method best identifies this risk?

Threat Intelligence and Advanced Threat Hunting: behavioral analytics for detecting insider threats Medium
A. Search only for malware signatures on the employee's computer
B. Compare the activity with the user's established behavioral baseline
C. Treat the download as safe because valid credentials were used
D. Block all customer-record access outside standard office hours

30 A privileged administrator regularly transfers large backup files as part of assigned duties. How should a behavioral analytics system reduce false positives for this activity?

Threat Intelligence and Advanced Threat Hunting: behavioral analytics for detecting insider threats Medium
A. Build role-aware baselines that include the administrator's normal duties
B. Alert whenever any user transfers more than one file
C. Exclude every privileged account from behavioral monitoring
D. Apply identical access thresholds to all organizational roles

31 A modern SOC is overwhelmed by alerts from endpoints, cloud platforms, and identity systems. Which capability most directly improves cross-environment investigation?

Emerging Trends and the Future of SOC Analysis: introduction Medium
A. Manual duplication of every alert into separate tracking systems
B. Centralized correlation of telemetry from multiple security sources
C. Longer retention of alerts without normalization or prioritization
D. Independent review of each tool without shared incident context

32 A SOC deploys machine learning to prioritize alerts. Which practice is most important for maintaining reliable results as attacker behavior changes?

Emerging Trends and the Future of SOC Analysis: emerging trends and the future of SOC analysis Medium
A. Monitor model performance and retrain it with relevant data
B. Allow the model to close every high-risk alert automatically
C. Remove analyst feedback from the model evaluation process
D. Keep the initial model unchanged to preserve consistency

33 How can generative AI most appropriately assist a SOC analyst during an investigation?

Emerging Trends and the Future of SOC Analysis: emerging trends and the future of SOC analysis Medium
A. Execute destructive containment actions without human approval
B. Assign threat attribution without supporting intelligence sources
C. Replace all telemetry collection with generated incident narratives
D. Summarize evidence and suggest queries for analyst validation

34 A company adopts several SaaS and infrastructure cloud providers. What is the most significant operational change required in its SOC?

Emerging Trends and the Future of SOC Analysis: impact of cloud security on SOC operations Medium
A. Integrate provider telemetry and understand shared-responsibility boundaries
B. Use endpoint antivirus as the sole source of cloud visibility
C. Transfer all detection responsibilities to the cloud providers
D. Monitor only physical network devices located in company offices

35 A SOC detects repeated cloud storage misconfigurations across multiple accounts. Which improvement would address the issue most effectively?

Emerging Trends and the Future of SOC Analysis: impact of cloud security on SOC operations Medium
A. Disable cloud audit logging to reduce the number of alerts
B. Review storage settings only during the annual compliance audit
C. Continuously evaluate configurations against approved security policies
D. Focus investigations only on storage systems already breached

36 Which development is most likely to increase the need for identity-focused detection in future SOC operations?

Emerging Trends and the Future of SOC Analysis: predicting future directions Medium
A. Growth in cloud services, remote access, and machine identities
B. Elimination of third-party access to organizational systems
C. Decline in the use of authentication for sensitive resources
D. Replacement of digital services with isolated paper processes

37 A SOC leader is planning for attackers who increasingly use automation. Which investment best prepares the SOC for this trend?

Emerging Trends and the Future of SOC Analysis: predicting future directions Medium
A. Complete reliance on static signatures created during deployment
B. Real-time analytics combined with controlled response automation
C. Monthly manual log reviews performed by a single analyst
D. Permanent suppression of alerts generated outside business hours

38 A SOAR playbook receives an alert about a suspicious email attachment. Which sequence is the most appropriate automated workflow?

Emerging Trends and the Future of SOC Analysis: SOAR Medium
A. Close the alert, archive the attachment, and remove related telemetry
B. Enrich the alert, assess risk, quarantine the email, and notify analysts
C. Delete all employee email, reset every password, and close the alert
D. Notify analysts, ignore enrichment, and permanently disable email

39 Which incident is the best candidate for initial SOAR implementation?

Emerging Trends and the Future of SOC Analysis: SOAR Medium
A. An unknown outage with no available telemetry or response procedure
B. A frequent phishing alert with stable and documented response steps
C. A rare nation-state intrusion requiring extensive strategic judgment
D. A legal investigation requiring case-specific executive decisions

40 A user authenticated successfully in the morning but later connects from an unmanaged device to a sensitive database. What should a zero-trust system do?

Emerging Trends and the Future of SOC Analysis: zero-trust security model Medium
A. Allow access because the user completed authentication earlier that day
B. Reevaluate identity, device posture, and access context before allowing access
C. Trust the connection because it originates from the corporate network
D. Grant permanent database access based only on the user's department

41 A threat-hunting team receives an intelligence report describing an adversary's preferred tools but no confirmed indicators of compromise. What is the most defensible first action?

Threat Intelligence and Advanced Threat Hunting: introduction Hard
A. Search only for the listed file hashes
B. Block every domain associated with the adversary
C. Translate the report into testable behavioral hypotheses
D. Wait until an internal alert confirms the report

42 Which combination best distinguishes advanced threat hunting from conventional alert-driven monitoring?

Threat Intelligence and Advanced Threat Hunting: introduction Hard
A. Centralized logging with longer retention periods
B. Automated blocking of all suspicious addresses
C. Higher alert volume with stricter severity thresholds
D. Continuous hypothesis testing across weak signals

43 A hunter wants to test whether an attacker is using valid accounts for lateral movement without relying on known malware signatures. Which approach is strongest?

Threat Intelligence and Advanced Threat Hunting: advanced threat-hunting methodologies Hard
A. Compare authentication paths with established user baselines
B. Search proxy logs for previously reported malware domains
C. Scan endpoints exclusively for unsigned executables
D. Block all logins occurring outside business hours

44 In a detection-engineering feedback loop, a hunt finds repeated benign administrative activity that triggers a high-confidence rule. What is the most appropriate next step?

Threat Intelligence and Advanced Threat Hunting: advanced threat-hunting methodologies Hard
A. Increase the rule severity to force analyst review
B. Delete the rule because it produced false positives
C. Refine the rule using contextual discriminators
D. Suppress all activity from the administrative account

45 Why should confidence, freshness, and provenance be attached to intelligence before it drives automated containment?

Threat Intelligence and Advanced Threat Hunting: lifecycle intelligence for automated response Hard
A. They determine whether an indicator can be safely acted upon
B. They eliminate the need for analyst review during incidents
C. They convert tactical indicators into permanent blocking rules
D. They guarantee that every indicator identifies a compromised host

46 An IP reputation feed marks a shared cloud address as malicious, but the address is now assigned to unrelated tenants. Which lifecycle control is most important before automated blocking?

Threat Intelligence and Advanced Threat Hunting: lifecycle intelligence for automated response Hard
A. Apply the block to every connected subnet
B. Increase the indicator's expiration period
C. Require contextual enrichment and confidence validation
D. Replace the IP indicator with a broader country block

47 Which design best prevents an automated response playbook from repeatedly re-triggering itself during an incident?

Threat Intelligence and Advanced Threat Hunting: lifecycle intelligence for automated response Hard
A. Route every repeated event to a separate analyst queue
B. Disable all response actions after the first execution
C. Increase the number of response actions per alert
D. Use idempotent actions with state tracking and suppression

48 A cloud hunter investigates suspected credential compromise. Which evidence set provides the strongest basis for identifying anomalous use of the credential?

Threat Intelligence and Advanced Threat Hunting: techniques for effective threat hunting in the cloud Hard
A. Login country and password age only
B. Cloud provider status pages and billing summaries
C. API calls, token context, resource paths, and timing
D. Endpoint antivirus results and local file names

49 A cloud storage exposure hunt produces inconsistent results because object access logs are absent in some accounts. What is the primary analytical limitation?

Threat Intelligence and Advanced Threat Hunting: techniques for effective threat hunting in the cloud Hard
A. The hunt can rely on network flow logs to reconstruct every object read
B. The hunt cannot distinguish absence of evidence from evidence of absence
C. The hunt will automatically overestimate the number of exposed objects
D. The hunt remains complete if identity-provider logs are available

50 Which cloud hunting strategy is most resilient to rapidly changing workloads and ephemeral resources?

Threat Intelligence and Advanced Threat Hunting: techniques for effective threat hunting in the cloud Hard
A. Track immutable hostnames across every deployment
B. Depend on fixed IP allowlists for workload attribution
C. Investigate only long-lived virtual machines
D. Prioritize identities, control-plane actions, and resource relationships

51 Why is a peer-group baseline generally preferable to a single global baseline for insider-threat detection?

Threat Intelligence and Advanced Threat Hunting: behavioral analytics for detecting insider threats Hard
A. It removes the need to understand job responsibilities
B. It makes rare but authorized actions impossible
C. It reduces legitimate-role variation being mistaken for abuse
D. It guarantees that anomalous behavior is malicious

52 An employee downloads unusually large datasets shortly before resignation, but the downloads match an approved migration project. Which response best reflects sound behavioral analytics?

Threat Intelligence and Advanced Threat Hunting: behavioral analytics for detecting insider threats Hard
A. Ignore the event because approved projects cannot be abused
B. Treat the event as malicious because the timing is suspicious
C. Disable the employee account until the investigation is complete
D. Correlate authorization, destination, scope, and project evidence

53 Which modeling error most directly increases false positives when detecting insider threats in a highly seasonal business?

Threat Intelligence and Advanced Threat Hunting: behavioral analytics for detecting insider threats Hard
A. Separating privileged users from ordinary users
B. Using a static baseline that ignores predictable seasonal changes
C. Including access times and data volume in the feature set
D. Requiring corroboration from multiple independent signals

54 What is the central analytical challenge created by the increasing automation of SOC operations?

Emerging Trends and the Future of SOC Analysis: introduction Hard
A. Maintaining human oversight over opaque and consequential decisions
B. Ensuring analysts manually execute every containment action
C. Eliminating the need for incident prioritization
D. Replacing all telemetry with endpoint-only measurements

55 A SOC adopts an AI-assisted detection system that lowers alert volume but occasionally suppresses novel attack patterns. Which metric pairing best exposes this trade-off?

Emerging Trends and the Future of SOC Analysis: emerging trends and the future of SOC analysis Hard
A. Mean time to acknowledge and analyst attendance
B. Number of dashboards and storage utilization
C. Alert count and total log ingestion
D. False-negative rate and detection coverage over attack techniques

56 In a multi-cloud environment, what operational change is most necessary for reliable SOC analysis?

Emerging Trends and the Future of SOC Analysis: impact of cloud security on SOC operations Hard
A. Assign each cloud provider to an isolated SOC with no correlation
B. Collect only perimeter firewall logs from each provider
C. Use one provider's native event schema without transformation
D. Normalize identity, resource, and action semantics across providers

57 Which capability is most likely to distinguish mature future SOCs from organizations that merely deploy more security tools?

Emerging Trends and the Future of SOC Analysis: predicting future directions Hard
A. A larger number of independent alert consoles
B. Maximum retention of every event without prioritization
C. Continuous validation of controls against adversary behavior
D. More frequent replacement of detection products

58 A SOAR playbook enriches an alert, isolates a host, and opens a ticket. Which design most appropriately limits operational risk?

Emerging Trends and the Future of SOC Analysis: SOAR Hard
A. Skip enrichment because containment is always the priority
B. Allow each integration to make independent containment decisions
C. Use severity gates, approval points, rollback steps, and audit logs
D. Execute all actions automatically for every matching alert

59 A zero-trust architecture detects a valid user accessing a sensitive application from a managed device. Which additional decision input is most important before granting access?

Emerging Trends and the Future of SOC Analysis: zero-trust security model Hard
A. The fact that the device is inside the corporate network
B. The user's historical login count alone
C. Continuous context including device posture and requested resource
D. A permanent allowlist entry for the user's department

60 Which SOC telemetry pattern most strongly indicates that a zero-trust policy is being bypassed through excessive privilege?

Emerging Trends and the Future of SOC Analysis: zero-trust security model Hard
A. Repeated access denials followed by successful authorized access
B. Routine access to low-sensitivity resources during working hours
C. Short sessions that access only assigned applications
D. Users authenticating through the organization's identity provider