Splunk Observability Cloud Certified Metrics User — Question 44

What is the main difference between hypothesis-driven and data-driven Threat Hunting?

Answer options

Correct answer: B

Explanation

The correct answer is B because data-driven hunting focuses on analyzing existing data to identify anomalies, while hypothesis-driven hunting is initiated by a specific theory about potential threats. The other options either misrepresent the processes of each type of hunting or incorrectly describe their execution and focus.