Uncover chapter quiz

Quiz

Uncover chapter quiz

No grades. The point is to push your thinking. Tap an option to see if it lands.

A threat intel feed says a particular domain is associated with a known campaign. The analyst sees the same domain in firewall logs from one host. What is the right next step?

A dropper hash matches a known campaign's tooling, and nothing else links the case to that actor. What confidence label can attribution carry in the case file?

Need a nudge?

The match is exact. The question is what else could explain it.

Which level of MITRE ATT&CK changes most often?

An investigation needs to know whether a file was executed on an endpoint earlier this week. Which data source answers this most directly?

An investigation needs both an EDR process timeline and a SIEM-wide authentication search. Which query runs first?

A suspected intrusion may have started six weeks ago, but the SOC's EDR retains 14 days of telemetry. Which data-source principle is at stake?

The Uncover narrative concludes with a chain of MITRE techniques. Why is the chain more useful than free-form prose?

An analyst is investigating a possible compromise on a macOS developer workstation. The user's role legitimately involves scripting, IDE plugin processes, and encrypted outbound traffic. What does the methodology require Uncover to produce if the evidence supports a benign verdict?

Risk receives an Uncover handoff. Which of these decisions is Risk authorized to make?

Need a nudge?

Risk is not response.

EDR records powershell.exe (PID 4416) opening an outbound connection at 14:22:31Z. The proxy logs a TLS session from the same host to a newly registered domain at 14:22:31Z. What makes treating these as one event defensible?

Need a nudge?

One matching field is coincidence-prone. Which fields together identify the event?

GuardDuty flags an engineer's 02:14 UTC AssumeRole into a role normally used only by CI, with read access to a regulated bucket. CloudTrail shows eight reads of quarterly-export files, no ListBucket reconnaissance, no writes, corporate VPN egress throughout. The IdP shows a FIDO2 login from the registered device with no token-replay or consent-grant indicators. What does Uncover conclude?

Need a nudge?

Separate two questions the evidence answers differently: who authenticated, and who authorized.

The case needs to answer one question before Risk: did data actually leave the environment? Which evidence combination answers it?

Next up

Transition to Risk

Continue