Review answers
The answers to the review questions are as follows:
- Regulation, policies, best practices. See the Regulatory requirements, legalities, and best practices section for more information.
- A, B. At a high level, an organization does concern itself with the standard traffic patterns and behaviors of users. Those items are extremely beneficial to defenders and administrators when identifying that something is wrong.
- External team. While an external team has higher short-term costs, an internal team will cost more to maintain and will normally come with organizational bias.
- An organization that wants to have a threat hunt conducted; an organization that is willing and capable of granting the necessary access and authority for the threat hunting team; an organization that is willing and capable of integrating the results of the threat hunt into their defenses and business processes; a threat hunting team with the appropriate processes, training, and equipment...