Root Cause, Threat Hunting, And Forensics for Security+
Short answer
Root cause analysis looks beyond the first visible symptom. If malware executed on a workstation, the root cause might be a phishing email, unpatched software, a weak macro policy, stolen credentials, missing application control, or a misconfigured endpoint control. Root cause analysis should identify what allowed the incident to happen so the organization can prevent recurrence. Removing malware without fixing the exploited weakness may only create a temporary recovery.
Why it appears on the exam
SY0-701 4.8: Explain root cause analysis, threat hunting, legal hold, chain of custody, acquisition, reporting, preservation, and e-discovery at Security+ depth.
Key concepts
Concept 1
Required terms
root cause analysis: determining the underlying condition that allowed an incident or failure to occur. threat hunting: proactive searching for signs of compromise, attacker behavior, or hidden threats that alerts may not have surfaced. digital forensics: collecting, preserving, analyzing, and reporting digital evidence in a defensible way. legal hold: a directive to preserve relevant information because litigation, investigation, or regulatory action is expected or underway.
Example
After a web server compromise, responders find the immediate malware and then determine the server was exploited through an unpatched application plugin. Identifying the unpatched plugin is root cause analysis.
Concept 2
How Root Cause, Threat Hunting, And Forensics works
Root cause analysis looks beyond the first visible symptom. If malware executed on a workstation, the root cause might be a phishing email, unpatched software, a weak macro policy, stolen credentials, missing application control, or a misconfigured endpoint control. Root cause analysis should identify what allowed the incident to happen so the organization can prevent recurrence. Removing malware without fixing the exploited weakness may only create a temporary recovery.
Example
Analysts suspect an attacker used a specific remote access tool but no alert fired. They search endpoint and network telemetry for related process names, registry keys, and outbound patterns. That is threat hunting.
Concept 3
Common confusion
Learners often confuse root cause analysis with eradication. Eradication removes the malicious condition or exploited weakness. Root cause analysis determines why the incident was possible so controls can be improved.
Example
A laptop may contain evidence for a legal case. The team preserves it, records chain of custody, acquires a forensic image, and stores the original securely.
Concept 4
What to recognize
Choose root cause analysis, threat hunting, digital forensics, legal hold, chain of custody, acquisition, reporting, preservation, or e-discovery based on scenario cues; Explain why chain of custody and preservation matter for evidence integrity; Distinguish proactive threat hunting from reactive alert triage; Recognize legal hold and e-discovery when legal preservation or production is the cue.
Example
The legal department expects litigation after a data breach and instructs teams not to delete relevant email or logs. That is a legal hold.
Sample questions
Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.
Q1.A Security+ scenario describes this situation: After a web server compromise, responders find the immediate malware and then determine the server was exploited through an unpatched application plugin. Identifying the unpatched plugin is root cause analysis. Which answer fits best?
Q2.A Security+ scenario describes this situation: Analysts suspect an attacker used a specific remote access tool but no alert fired. They search endpoint and network telemetry for related process names, registry keys, and outbound patterns. Which answer fits best?
Q3.A security team needs to decide what this situation represents: A laptop may contain evidence for a legal case. The team preserves it, records chain of custody, acquires a forensic image, and stores the original securely. Which option fits?
Practice this lesson in Cultiv8
The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.
Continue in Cultiv8