What should a security analyst do when SIEM alerts are not configured for a new threat?
A cyber operations team informs a security analyst about a new tactic malicious actors are using to compromise networks. SIEM alerts have not yet been configured. Which of the following best describes what the security analyst should do to identify this behavior?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the distinction between reactive and proactive security measures, with the common trap being to select incident response or digital forensics, which are reactive rather than proactive.
When SIEM alerts are not yet configured for a new malicious tactic, threat hunting is the proactive approach used to identify suspicious behavior and indicators of compromise. The community consensus strongly supports threat hunting as the correct response in this scenario.
Many candidates incorrectly choose 'Incident response' or 'Digital forensics' because they associate these with investigating threats, but these are reactive measures taken after an alert or breach, not proactive identification methods.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Threat hunting is a proactive security practice that involves actively searching for threats that have evaded existing detection mechanisms. Since the SIEM alerts have not been configured for this new tactic, the security analyst must manually investigate network logs, endpoints, and other data sources to identify suspicious behavior. This aligns perfectly with the definition of threat hunting as described in the CompTIA Security+ SY0-701 objectives. Community comments [1], [2], and [3] all emphasize the proactive nature of threat hunting in this scenario.Why the Other Options Are Wrong
Digital forensics (A) is a reactive process used to collect and analyze evidence after an incident has occurred, not to proactively identify new threats. E-discovery (B) refers to the legal process of identifying and collecting electronic information for litigation, which is unrelated to identifying network threats. Incident response (C) is a reactive process that is triggered after a security incident has been detected, typically through alerts or other notifications. Since no SIEM alerts have been configured, there is no trigger for incident response.Community Comment Notes
The community unanimously agrees that D is the correct answer, with comment [1] providing a comprehensive explanation of threat hunting's proactive nature. Comment [4] succinctly captures the essence of the scenario: 'If the SIEM ain't been configured, then you gotta go look for the threat.' All comments emphasize the distinction between proactive threat hunting and reactive security measures.Official Reference
Exam Strategy
When a question describes a scenario where existing security controls (like SIEM alerts) are not configured for a new threat, look for the proactive approach. Threat hunting is the correct answer when the question asks how to identify threats that have bypassed or are not yet detected by existing security measures.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →