CISSP · Free practice question 9 of 12
Proactive hypothesis-driven threat hunting
After reading a threat intelligence report about a group that targets logistics firms, analysts at Morland Freight form a hypothesis about how the group would operate and search their own logs and endpoints for those traces, even though no alert has fired. What activity are they performing?
- A.Penetration testing
- B.Threat hunting
- C.Vulnerability scanning
- D.Incident triage
Show answer and explanation
Correct answer: B. Threat hunting
Why: Threat hunting is a proactive, often hypothesis-driven search for signs of adversaries that existing controls may have missed, frequently guided by threat intelligence. Vulnerability scanning looks for weaknesses rather than intruders, incident triage begins only after an alert or report, and penetration testing simulates an attack instead of searching for real attacker activity.
More free CISSP questions
- Senior management ultimate security accountability
- Wassenaar Arrangement export of cryptography
- Brewer-Nash model prevents conflicts of interest
- Known-plaintext cryptanalytic attack
- Air-gapped network physical segmentation
- Role-based access control by job function
- Misuse case testing of abuse scenarios
- Breach and attack simulation platforms
- Lessons learned after incident closure
- Access control vestibule stops tailgating
- Cold site characteristics and recovery time