Question 1. After a peer company reports an intrusion that persisted through scheduled tasks, a hunt team wants to check its own finance workstations. Before it queries any EDR telemetry, what should the team define FIRST?
- AAn isolation plan that disconnects every finance workstation during the hunt
- BA blocklist built from the file hashes published in the peer company's report
- CA testable hypothesis mapped to an ATT&CK technique and the data needed to test it
- DAn authenticated vulnerability scan schedule covering all finance endpoints
Show the answer
Correct answer: C. A testable hypothesis mapped to an ATT&CK technique and the data needed to test it
Structured threat hunting starts with a hypothesis, here mapped to the ATT&CK scheduled task technique, that names the telemetry needed to prove or disprove it. Blocking the peer's hashes only catches that exact sample and is not a hunt.