Question 4 of 10Pro Only

How do you use the MITRE ATT&CK framework to plan and execute a threat hunt? Walk me through how you would select techniques to hunt for and how you would determine whether your environment has the data needed to detect them.

Sample answer preview

The MITRE ATT&CK framework is one of the most valuable tools for structuring threat hunting activities because it provides a comprehensive, categorized catalog of adversary tactics and techniques observed in real-world attacks. Here is how I use it to plan and execute hunts.

MITRE ATT&CKtechnique selectiondata source assessmenthunting queriesdetection coverageATT&CK Navigator

Unlock the full answer

Get the complete model answer, key points, common pitfalls, and access to 9+ more SOC Analyst interview questions.

Upgrade to Pro

Starting at $19/month • Cancel anytime