Review answers
The answers to the review questions are as follows:
- C, F. While many people may receive a report after a threat hunt, it is up to the owning organization to release it beyond the initial stakeholders participating in the threat hunt.
- Operator, C2. The easiest way to view this is to remember that the operator channel provides the operators an open forum to discuss without worry or interference from those that might read into what is said.
- State only facts. See Communicating with business owners for more details on why this matters.
- True. Remember that everything a team does can, and normally will, be viewed by others including an adversary that is active on the same network. This observation is an indirect form of communication.
- False. Everything an individual does or says will be interpreted as a form of communication.