Question 1

A threat hunter wants to prioritize investigations according to attacker objectives, techniques, and operational tactics. Which framework provides the best alignment?
  • Question 2

    Based on the Malware profile image below, what happens when a new custom-developed application attempts to execute on an endpoint?
  • Question 3

    A threat hunter suspects lateral movement activity involving compromised credentials. Which telemetry combination provides the strongest evidence during investigation?
  • Question 4

    An organization experiences recurring malware alerts from the same endpoint despite repeated remediation efforts. What should investigators examine first?
  • Question 5

    Which XQL query can be saved as a behavioral indicator of compromise (BIOC) rule, then converted to a custom prevention rule?