nerdexam
Cisco

300-220 · Question #106

When selecting indicators for attribution, which of the following is considered a weak indicator on its own?

The correct answer is B. Time of attack. Time of attack (B) is a weak standalone indicator because many threat actors operate across time zones, use automated tools, or deliberately shift their schedules to mislead analysts - making timing alone statistically unreliable for confident attribution. Why the distractors…

Threat Actor Attribution Techniques

Question

When selecting indicators for attribution, which of the following is considered a weak indicator on its own?

Options

  • AA unique tool or piece of malware
  • BTime of attack
  • CSpecificity of the target
  • DLanguage of the attack code

How the community answered

(39 responses)
  • A
    5% (2)
  • B
    72% (28)
  • C
    15% (6)
  • D
    8% (3)

Explanation

Time of attack (B) is a weak standalone indicator because many threat actors operate across time zones, use automated tools, or deliberately shift their schedules to mislead analysts - making timing alone statistically unreliable for confident attribution.

Why the distractors are wrong:

  • A (Unique tool/malware): Custom or rare malware is a strong indicator because it ties activity to specific developers or groups; signatures, code patterns, and reuse across campaigns are highly attributable.
  • C (Specificity of target): A narrowly scoped victim (e.g., a single government agency or niche industry) suggests deliberate intent and insider knowledge, which narrows the suspect pool significantly.
  • D (Language of attack code): Hardcoded strings, error messages, or comments in a specific language or locale provide meaningful cultural/geographic signals - though skilled actors can spoof this.

Memory tip: Think of time as the weakest link - anyone can set an alarm clock or schedule a script to fire at 3 AM Tokyo time. But a custom exploit or precision targeting takes real knowledge and effort that leaves a fingerprint.

Topics

#attribution indicators#indicator strength#threat actor profiling#indicator evaluation

Community Discussion

No community discussion yet for this question.

Full 300-220 Practice