Testing yourself
This section is meant to be a little test of the content from this and the previous chapter. Try to answer the following questions from memory to see how much of what you have been reading you have remembered:
- What do MOPs and MOEs stand for?
A) Measures of Efficacy and Measures of Performance
B) Measures of Efficacy and Measures of Presentation
C) Measures of Effectiveness and Measures of Performance
- True or false: You must always make the number of hunts made by each member of the team an indicator of success.
A) True
B) False
- Which of the following is not a proposed metric?
A) Number of hypotheses
B) Number of new detections generated
C) Number of team meetings
- How many levels does the Threat Hunting Maturity Model have?
A) 5
B) 4
C) 6
- What are the three MaGMA for Threat Hunting layers?
A) The ATT&CK tactics, the attack types, and the executed hunts
B) The kill chain steps, the attack types, and the executed hunts
C) The kill chain steps, the ATT...