nerdexam
Cisco

200-201 · Question #37

Which piece of information is needed for attribution in an investigation?

The correct answer is C. known threat actor behavior. Known threat actor behavior refers to established patterns, techniques, tactics, procedures, or behaviors previously associated with specific threat actors or hacking groups. Understanding and recognizing the behavior patterns of known threat actors, their modus operandi…

Submitted by miguelv· Mar 6, 2026Security Monitoring

Question

Which piece of information is needed for attribution in an investigation?

Options

  • Aproxy logs showing the source RFC 1918 IP addresses
  • BRDP allowed from the Internet
  • Cknown threat actor behavior
  • D802.1x RADIUS authentication pass arid fail logs

How the community answered

(56 responses)
  • A
    16% (9)
  • B
    7% (4)
  • C
    73% (41)
  • D
    4% (2)

Explanation

Known threat actor behavior refers to established patterns, techniques, tactics, procedures, or behaviors previously associated with specific threat actors or hacking groups. Understanding and recognizing the behavior patterns of known threat actors, their modus operandi, tools, or tactics they commonly employ, can assist in attributing an attack or incident to a particular threat actor or

Topics

#attribution#threat actor#incident investigation

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice