A SOC analyst is asked to improve threat hunting for a hybrid environment with critical file servers, cloud workloads, and identity services. Which approach best uses threat modeling to focus detection effort?
Select an answer to reveal the explanation.
Short Explanation
Think of hunting like patrolling a city: you don’t stake out every alley. You look at who’s likely to break in and what’s most valuable, then focus there. That’s threat modeling — adversaries plus critical assets — not chasing the loudest dashboard.
Full Explanation
Threat modeling asks who is likely to target the environment, what they want, and how they might do it. When an analyst maps likely adversaries to critical assets, hunting and monitoring can be prioritized around high-value systems, common initial access paths, and techniques those actors are known to use. This keeps detection effort aligned with business impact rather than tool output volume. A generic attempt to cover every ATT&CK technique spreads resources thin and creates low-quality detections without context; ATT&CK is a lens for organizing coverage, not a checklist that automatically sets priority. Basing queues on SIEM alert volume mistakes noise for risk, because misconfigured sources, verbose services, and benign activity can dominate events while stealthy threats remain underrepresented. Using only CVSS scores from scanning ignores adversary intent, asset value, exposure, compensating controls, and likelihood; a critical server may have lower CVSS than an internet-facing test system. Exam caveat: CompTIA expects threat modeling to connect adversary behavior to critical assets and detection priorities, not simply to alert counts or vulnerability scores. Operational check: build a hunting backlog by pairing each critical asset with relevant ATT&CK techniques, adversary profiles, and data sources such as EDR, NetFlow, and identity logs.