フリー問題

CCNA Cybersecurity のフリー問題 3 / 20 問目

問題文

A team sets aside four hours a week during which an analyst forms a hypothesis such as "a compromised host would be resolving many newly registered domains" and then searches the stored records for that pattern, even though no alert has fired. What is this activity called, and what makes it different from working an alert queue?

選択肢

  1. Reverse engineering, because the analyst is inferring intent from a pattern rather than reading it from a description shipped with the sample.
  2. Malware analysis, because the goal is to learn how a sample behaves before it is seen in the environment, and the four-hour window is the time the sample needs to finish running inside an isolated machine.
  3. Run book automation, because the four-hour window follows one documented sequence of steps that the analyst repeats in the same order each week.
  4. Threat hunting, because the search starts from a hypothesis rather than from a detection that already fired.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。