200-201 · Question #37
Which piece of information is needed for attribution in an investigation?
The correct answer is C. known threat actor behavior. Known threat actor behavior refers to established patterns, techniques, tactics, procedures, or behaviors previously associated with specific threat actors or hacking groups. Understanding and recognizing the behavior patterns of known threat actors, their modus operandi…
Question
Which piece of information is needed for attribution in an investigation?
Options
- Aproxy logs showing the source RFC 1918 IP addresses
- BRDP allowed from the Internet
- Cknown threat actor behavior
- D802.1x RADIUS authentication pass arid fail logs
How the community answered
(56 responses)- A16% (9)
- B7% (4)
- C73% (41)
- D4% (2)
Explanation
Known threat actor behavior refers to established patterns, techniques, tactics, procedures, or behaviors previously associated with specific threat actors or hacking groups. Understanding and recognizing the behavior patterns of known threat actors, their modus operandi, tools, or tactics they commonly employ, can assist in attributing an attack or incident to a particular threat actor or
Topics
Community Discussion
No community discussion yet for this question.