An analyst in a hybrid SOC notices EDR alerts for task creation on several servers and wants to hunt for attacker persistence via scheduled tasks. Which action best represents forming a testable hunting hypothesis?
Select an answer to reveal the explanation.
Short Explanation
Think of hunting like fishing: you don't cast everywhere, you pick a spot and ask a question. If you want scheduled-task persistence, hunt for suspicious schtasks or task XML, not every task on every host. That hypothesis keeps your hunt focused and testable.
Full Explanation
Threat hunting is hypothesis-driven, so the analyst starts with a bounded, testable question and then selects telemetry that can confirm or refute it. In this case, the hypothesis is that adversary persistence may be implemented through scheduled tasks with unusual names, commands, or parent processes. The analyst tests it by querying task-creation or task-modification events, comparing task properties to baseline activity, and pivoting to process, file, or network telemetry when a pattern appears. A full inventory of every scheduled task is data collection, not hunting, because it lacks a focused question and quickly becomes unmanageable in a hybrid estate. A broad alert on every task creation event is detection engineering; it may generate useful telemetry, but it does not start from a specific adversary behavior and usually creates alert fatigue. Searching for all task-related executables and treating their presence as persistence is also too broad, since legitimate task services run constantly and the query does not distinguish benign from malicious activity. Exam caveat: CompTIA expects threat hunting to be framed as a testable hypothesis, not as a scan, inventory, or generic alert. Operational check: Build a hunting query for scheduled-task creation events, filter on rare task names, encoded commands, or suspicious parent processes, and validate results against known-good task baselines.