Protego field desk
Security Operations, Identity and Compliance / 25-30% of exam

L6.Incident Response, Threat Hunting & ATT&CK Coverage

Course outlineLesson 6 of 18

Design operational workflows that connect detections to incident ownership, threat hunting, evidence preservation, containment, recovery, and measured ATT&CK coverage.

Build one incident lifecycle

Define how alerts become incidents, who triages them, when severity changes, and which teams own containment and recovery. The workflow must work across cloud, identity, endpoint, mobile, and industrial environments when those assets are in scope.

Use ATT&CK as a coverage model

MITRE ATT&CK helps map adversary behaviors to data sources and detections. A technique marked as covered should have a working signal, tested analytic, triage procedure, and response action. Heat maps without validation can create false confidence.

Separate hunting from alert response

Alert response starts from a known signal. Threat hunting begins with a hypothesis and searches for evidence that current detections may miss. Productize successful hunts into analytics, enrichment, or collection improvements.

Preserve evidence and learning

Containment should consider evidence, business impact, and attacker persistence. Record decisions and timestamps, protect investigation data, and run lessons-learned reviews. Feed missed signals and slow handoffs back into engineering work. Architecture outcome: Security operations should reduce time to understand and contain material incidents, not merely increase alert volume.

Exam Focus Points
  • Define triage, severity, containment, recovery, and business ownership in one workflow
  • Validated ATT&CK coverage needs telemetry, analytics, procedures, and response
  • Threat hunting is hypothesis-driven and should improve future detection
  • Containment decisions balance evidence preservation and business impact
Knowledge Check

1. When can an ATT&CK technique reasonably be considered covered?