Splunk Certified Cybersecurity Defense Analyst SPLK-5001 Question # 2 Topic 1 Discussion

Splunk Certified Cybersecurity Defense Analyst SPLK-5001 Question # 2 Topic 1 Discussion

SPLK-5001 Exam Topic 1 Question 2 Discussion:
Question #: 2
Topic #: 1

What is the main difference between hypothesis-driven and data-driven Threat Hunting?


A.

Data-driven hunts always require more data to search through than hypothesis-driven hunts.


B.

Data-driven hunting tries to uncover activity within an existing data set, hypothesis-driven hunting begins with a potential activity that the hunter thinks may be happening.


C.

Hypothesis-driven hunts are typically executed on newly ingested data sources, while data-driven hunts are not.


D.

Hypothesis-driven hunting tries to uncover activity within an existing data set, data-driven hunting begins with an activity that the hunter thinks may be happening.


Get Premium SPLK-5001 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.