Review answers
The answers to the review questions are as follows:
- False. Cyber threat hunting is proactive as the hunter does not wait for an alarm or alert before searching for malicious behavior.
- C. See NIST SP 800-61r2 incident response life cycle.
- Detection and Analysis. See NIST SP 800-61r2 incident response life cycle.
- False. The threat hunting concept is used in many different fields.
- False positive; False negative. See the Application of detection levels section of this chapter.