What should a security analyst do when SIEM alerts are not configured for a new threat?

A cyber operations team informs a security analyst about a new tactic malicious actors are using to compromise networks. SIEM alerts have not yet been configured. Which of the following best describes what the security analyst should do to identify this behavior?

  1. Digital forensics
  2. E-discovery
  3. Incident response
  4. Threat hunting Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the distinction between reactive and proactive security measures, with the common trap being to select incident response or digital forensics, which are reactive rather than proactive.

When SIEM alerts are not yet configured for a new malicious tactic, threat hunting is the proactive approach used to identify suspicious behavior and indicators of compromise. The community consensus strongly supports threat hunting as the correct response in this scenario.

Many candidates incorrectly choose 'Incident response' or 'Digital forensics' because they associate these with investigating threats, but these are reactive measures taken after an alert or breach, not proactive identification methods.

Community Discussion (6 comments)

metzen227 👍 16
Threat hunting: Threat hunting involves proactively searching for and identifying potential security threats or indicators of compromise (IOCs) within an organization's network environment. It typically involves the use of advanced analytics, threat intelligence, and specialized tools to detect suspicious behavior or anomalies that may indicate the presence of a threat actor. In the scenario described, where SIEM alerts have not yet been configured to detect the new tactic malicious actors are using, the most appropriate action for the security analyst is Threat hunting. By engaging in threat hunting activities, the security analyst can proactively search for signs of the new tactic within the network environment, helping to identify and mitigate potential security risks before they escalate into full-blown incidents.
SHADTECH123 👍 6 Selected: D
Threat hunting involves proactive searching for signs of compromise or suspicious activities within the network. Since SIEM alerts have not been configured to detect the new tactic, engaging in threat hunting allows the security analyst to actively search for indicators of compromise and emerging threats before they escalate into security incidents.
itone333 👍 1 Selected: D
If the SIEM ain't been configured, then you gotta go look for the threat..
kai001 👍 1 Selected: D
Threat hunting is a proactive approach used by security analysts to search for signs of malicious activity that might have bypassed existing security measures, such as SIEM alerts. Since the SIEM has not been configured for this new tactic, threat hunting allows the analyst to manually investigate network traffic, logs, endpoints, and other data sources to identify suspicious behavior based on the new information provided by the cyber operations team.
dbrowndiver 👍 2 Selected: D
In this scenario, the security analyst needs to proactively search for signs of the new malicious tactic being used in the network, especially since SIEM alerts are not yet configured to detect this behavior. • Scenario Application: Proactive Investigation: With the lack of SIEM alerts, threat hunting allows the analyst to manually search for indicators of the new tactic within network logs, endpoint data, and other security information sources. Adaptability: Threat hunters adapt their techniques based on new intelligence, such as the information provided by the cyber operations team, to identify potential threats that automated systems might miss. Threat hunting is particularly useful when dealing with new or unknown attack tactics that have not yet been incorporated into automated detection systems. By manually analyzing the environment, analysts can identify and understand the behavior of threats, leading to better future alert configurations.
hasquaati 👍 1 Selected: D
Good answer

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Threat hunting is a proactive security practice that involves actively searching for threats that have evaded existing detection mechanisms. Since the SIEM alerts have not been configured for this new tactic, the security analyst must manually investigate network logs, endpoints, and other data sources to identify suspicious behavior. This aligns perfectly with the definition of threat hunting as described in the CompTIA Security+ SY0-701 objectives. Community comments [1], [2], and [3] all emphasize the proactive nature of threat hunting in this scenario.

Why the Other Options Are Wrong

Digital forensics (A) is a reactive process used to collect and analyze evidence after an incident has occurred, not to proactively identify new threats. E-discovery (B) refers to the legal process of identifying and collecting electronic information for litigation, which is unrelated to identifying network threats. Incident response (C) is a reactive process that is triggered after a security incident has been detected, typically through alerts or other notifications. Since no SIEM alerts have been configured, there is no trigger for incident response.

Community Comment Notes

The community unanimously agrees that D is the correct answer, with comment [1] providing a comprehensive explanation of threat hunting's proactive nature. Comment [4] succinctly captures the essence of the scenario: 'If the SIEM ain't been configured, then you gotta go look for the threat.' All comments emphasize the distinction between proactive threat hunting and reactive security measures.

Official Reference

Exam Strategy

When a question describes a scenario where existing security controls (like SIEM alerts) are not configured for a new threat, look for the proactive approach. Threat hunting is the correct answer when the question asks how to identify threats that have bypassed or are not yet detected by existing security measures.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide