Question 1
A threat hunter wants to prioritize investigations according to attacker objectives, techniques, and operational tactics. Which framework provides the best alignment?
Question 2
Based on the Malware profile image below, what happens when a new custom-developed application attempts to execute on an endpoint?


Question 3
A threat hunter suspects lateral movement activity involving compromised credentials. Which telemetry combination provides the strongest evidence during investigation?
Question 4
An organization experiences recurring malware alerts from the same endpoint despite repeated remediation efforts. What should investigators examine first?
Question 5
Which XQL query can be saved as a behavioral indicator of compromise (BIOC) rule, then converted to a custom prevention rule?
