Review questions
Answer the following to check your knowledge of this chapter:
- _________-driven collection methods are concerned with collecting and storing only the things that are known to the team and that they might care about.
- _________-driven collection methods are concerned with collecting and storing everything possible.
- _________ collection methods are concerned with a combination of the other two.
- (True or False) Secondary correlation is making an inference about something without directly observing it.
- (True or False) When conducting a threat hunt, the main goal that matters is finding an adversary.