WorksheetsDay 3 - Blue team
Total questions: 5
Worksheet time: 3mins
Name
Class
Date
1.
MITRE ATT&CK only documents malware families, not attacker techniques or tactics
a)
True
b)
False
2.
Threat Hunting assumes that attackers may already be inside the environment, even if no alerts were triggered
a)
True
b)
False
3.
What is the first step in the Threat Hunting process?
a)
Identify IOCs
b)
Build a timeline
c)
Formulate a hunting hypothesis
d)
Create a final report
4.
Which log source is most useful for detecting suspicious PowerShell execution?
a)
DNS Logs
b)
Firewall Logs
c)
Windows Event Logs / Sysmon (Event ID 4104)
d)
Antivirus Logs
5.
What is the primary goal of a Blue Team CTF?
a)
Compromise servers
b)
Test malware in production
c)
Detect, analyze, and respond to an active threat
d)
Hide IOCs from analysts
100 %
