AI Bot

Threat Hunting Techniques & Indicators Flashcards

CompTIA CySA+ CS0-004 (V4) Flashcards

Study our Threat Hunting Techniques & Indicators flashcards for the CompTIA CySA+ CS0-004 (V4) exam with 42+ flashcards. View as flashcards, a searchable table, or as a fun matching game.
CompTIA CySA+ CS0-004 (V4) Course Header Image
FrontBack
Best practice for managing false positivesIteratively tune detections and document legitimate baselines to reduce noise
Common host data sourcesProcess logs file system events autoruns EDR telemetry and system audit logs
Common network data sourcesNetflow packet captures proxy logs DNS logs and firewall logs
Define hypothesis driven huntingAn investigative approach that starts with a testable assumption about potential adversary activity to guide data collection and analysis
Describe enrichmentAdding context like asset owner geolocation or threat intel to raw telemetry to improve analysis
Explain query strategy broad to narrowStart with wide data queries to identify anomalies then refine to isolate true positives
Explain query strategy hypothesis drivenDesign queries specifically to test the hunting hypothesis using relevant telemetry
Give an example of a high value artifact for pivotingAuthentication logs that show unusual logon sequences or host access
How to handle high confidence IOC found in productionIsolate affected assets collect volatile evidence and escalate to containment and remediation
How to reduce detection gapsMap telemetry to ATT&CK identify missing coverage and deploy sensors or rules to collect needed data
How to validate a suspected IOCCorrelate across multiple data sources and reconstruct activity timeline to confirm maliciousness
How use threat intel to prioritize huntsFocus on intel linked to your environment like targeted industries or known exploited services
IOA definitionIndicator of Attack behavior pattern or sequence that suggests intent or ongoing malicious activity
IOC definitionIndicator of Compromise observable artifact like file hash IP or domain that signals past or current compromise
Key metrics for hunting successDetections validated time to detect time to remediate and reduction in false positives
List the typical hunt phasesPreparation Detection Hypothesis Investigation Validation and Remediation
Primary difference between IOC and IOAIOC is static evidence of compromise IOA reflects behavior or intent
Purpose of hunting exercises like purple teamingTest and improve detection by collaborating between offensive and defensive teams
Role of EDR in huntingProvides rich endpoint telemetry process and command line details for detection and containment
Role of PCAP and full packet captureEnables deep protocol level analysis and reconstruction of network sessions for validation
Role of SIEM in huntingAggregates logs correlates events and enables searching across diverse telemetry at scale
What are TTPs in threat huntingTactics Techniques and Procedures used by adversaries to achieve objectives
What belongs in the Preparation phaseDefine hypothesis identify data sources ensure telemetry and tools are available
What is a false positive in huntingAn alert or finding that appears malicious but is benign on investigation
What is a hunting playbookA repeatable documented procedure for conducting a specific hunt including queries and evidence collection
What is a hypothesis in huntingA falsifiable statement about malicious activity to be tested with data
What is a kill chain in huntingSequential stages of an intrusion used to map detections and identify gaps in coverage
What is an enriched IOCAn IOC combined with context such as first seen time asset owner and related alerts
What is baseline behaviorNormal activity patterns for users systems and applications used to detect anomalies
What is behavioral analyticsDetecting deviations from normal behavior patterns to identify suspicious activity
What is dwell timeThe duration an adversary remains in an environment before detection
What is enrichment via external feedsAugmenting telemetry with reputation tags vulnerability data or actor attribution from feeds
What is hypothesis prioritizationPrioritizing hunts based on impact likelihood and data availability
What is pivoting in an investigationUsing one artifact to find related artifacts or hosts to expand scope of activity
What is threat intelligence integrationIngesting and applying external context like adversary TTPs indicators and reports to inform hunts
What is timeline analysisReconstructing sequence of events across data sources to understand attacker actions and scope
When to use anomaly detectionWhen you lack signatures for novel or evolving attacker behavior
When to use host logs vs network logsUse host logs for process file and user activity and network logs for lateral movement and data exfiltration
Why document hunt resultsPreserves lessons learned enables reuse of methods and supports remediation and reporting
Why retention mattersLonger telemetry retention enables detection of long dwell attackers and historical investigations
Why threat modeling matters for huntingHelps prioritize likely attack paths assets and controls to focus hypotheses
Why use ATT&CK in huntingProvides a common framework to map adversary behaviors to techniques and gaps

About the Flashcards

Flashcards for the CompTIA CySA+ exam help students review threat hunting terminology, including hypotheses, adversary TTPs, indicators of compromise, indicators of attack, dwell time, and baseline behavior. The deck also explains typical hunt phases, prioritization methods, investigation strategies, and documentation practices.

Students can reinforce their understanding of host and network telemetry, EDR, SIEM, packet capture, ATT&CK mapping, and threat intelligence integration. Additional cards cover anomaly detection, query refinement, pivoting, enrichment, timeline analysis, false-positive reduction, detection validation, remediation, hunting metrics, playbooks, and purple team exercises.

Topics covered in this flashcard deck:

  • Threat hunting fundamentals
  • IOCs, IOAs, and TTPs
  • Hunt phases and hypotheses
  • Telemetry and security tools
  • Investigation and validation
  • ATT&CK and threat intelligence
Share on...
Follow us on...