問題文
A team sets aside four hours a week during which an analyst forms a hypothesis such as "a compromised host would be resolving many newly registered domains" and then searches the stored records for that pattern, even though no alert has fired. What is this activity called, and what makes it different from working an alert queue?
選択肢
- Reverse engineering, because the analyst is inferring intent from a pattern rather than reading it from a description shipped with the sample.
- Malware analysis, because the goal is to learn how a sample behaves before it is seen in the environment, and the four-hour window is the time the sample needs to finish running inside an isolated machine.
- Run book automation, because the four-hour window follows one documented sequence of steps that the analyst repeats in the same order each week.
- Threat hunting, because the search starts from a hypothesis rather than from a detection that already fired.