CertKeen

CISSP · Free practice question 9 of 12

Proactive hypothesis-driven threat hunting

After reading a threat intelligence report about a group that targets logistics firms, analysts at Morland Freight form a hypothesis about how the group would operate and search their own logs and endpoints for those traces, even though no alert has fired. What activity are they performing?

  1. A.Penetration testing
  2. B.Threat hunting
  3. C.Vulnerability scanning
  4. D.Incident triage
Show answer and explanation

Correct answer: B. Threat hunting

Why: Threat hunting is a proactive, often hypothesis-driven search for signs of adversaries that existing controls may have missed, frequently guided by threat intelligence. Vulnerability scanning looks for weaknesses rather than intruders, incident triage begins only after an alert or report, and penetration testing simulates an attack instead of searching for real attacker activity.

More free CISSP questions