Home Quizzes Quiz Detail
Practice Quiz

ATT&CK Threat Hunting Practice Questions - MITRE ATT&CK Threat Hunting and Detection Engineering (MAD20) Exam

100 questions 5.0 rating Mobile friendly
$69.00

Unlock the full practice quiz

Get complete access to the questions, explanations and printable quiz resources.

Full access: unlock all quiz questions and explanations.
Printable review: access the full quiz PDF with correct answers after purchase.

About this Exam

Prepare with the ATT&CK Threat Hunting Practice Questions - MITRE ATT&CK Threat Hunting and Detection Engineering (MAD20) Exam practice quiz. This question bank includes 100 questions covering threat, mad20, hunt, technique, and hunter. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

Sample Questions

Question 1
Which of the following best describes the primary goal of a TTP-based threat hunt as taught in the MAD20 ATT&CK Threat Hunting methodology?
Proactively searching for adversary behaviors using ATT&CK techniques as the model of malicious activity
Reactively investigating alerts generated by SIEM correlation rules
Performing a vulnerability scan to identify unpatched systems
Building firewall rules based on known malicious IP addresses
Question 2
In the MAD20 six-step TTP-based threat hunt methodology, what is the correct order of the first two steps?
Identify adversary behaviors of interest, then develop hypotheses
Implement analytics, then develop hypotheses
Collect data, then identify adversary behaviors
Execute the hunt, then identify adversary behaviors
Question 3
Which ATT&CK construct represents the 'why' behind an adversary action—the goal the adversary is trying to achieve?
Technique
Procedure
Tactic
Sub-technique
Question 4
A threat hunter wants to focus hunting activity on techniques most likely used by a specific threat group targeting their industry. Which ATT&CK resource directly maps known adversary groups to the techniques they have been observed using?
ATT&CK Data Sources catalog
ATT&CK Navigator heat-map layers
ATT&CK Groups pages
ATT&CK Mitigations catalog
Question 5
When developing a threat hunt hypothesis in the MAD20 methodology, what essential element must the hypothesis contain to be actionable?
A specific, testable statement about observable adversary behavior linked to one or more ATT&CK techniques
A list of SIEM alert rule IDs that currently fire
A complete data-collection plan with all required log sources already confirmed available
A list of CVEs associated with the suspected adversary group

Ready to test your knowledge?

Buy Now to Access

Additional Information

ATT&CK Threat Hunting Practice Questions - MITRE ATT&CK Threat Hunting and Detection Engineering (MAD20) Exam

This practice set contains 100 questions from the matching question bank and focuses on threat, mad20, hunt, technique, and hunter. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Frequently Asked Questions

This quiz contains a total of 100 practice questions carefully selected to test your knowledge on this subject.
Yes, you will have exactly 0 minutes to complete the exam. A countdown timer will be visible once you start.
Yes, you can retake this practice test as many times as you need. The questions and options may be randomized on subsequent attempts to ensure comprehensive learning.

Reviews

5.0

Based on 0 reviews

Leave a Review

No reviews yet. Be the first to review!