nerdexam
Cisco

200-201 · Question #227

An engineer is analyzing a recent breach where confidential documents were altered and stolen by the receptionist. Further analysis shows that the threat actor connected an externa USB device to…

The correct answer is C. receptionist and the actions performed. Cyber Attribution: In an investigation, it is the process of identifying the threat actors who are responsible for an attack. It involves collecting and analyzing various types of data, including network logs, malware samples, social media activity, and other intelligence…

Submitted by wei.xz· Mar 6, 2026Host-Based Analysis

Question

An engineer is analyzing a recent breach where confidential documents were altered and stolen by the receptionist. Further analysis shows that the threat actor connected an externa USB device to bypass security restrictions and steal data. The engineer could not find an external USB device. Which piece of information must an engineer use for attribution in an investigation?

Options

  • Alist of security restrictions and privileges boundaries bypassed
  • Bexternal USB device
  • Creceptionist and the actions performed
  • Dstolen data and its criticality assessment

How the community answered

(47 responses)
  • A
    9% (4)
  • B
    2% (1)
  • C
    83% (39)
  • D
    6% (3)

Explanation

Cyber Attribution: In an investigation, it is the process of identifying the threat actors who are responsible for an attack. It involves collecting and analyzing various types of data, including network logs, malware samples, social media activity, and other intelligence sources, to identify the individuals, groups, or nations responsible for the attack.

Topics

#incident response#attribution#forensics#insider threat

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice