nerdexam
Cisco

300-220 · Question #120

Identifying a threat actor's tactics involves understanding their:

The correct answer is B. Overall objectives and goals. Tactics in threat intelligence frameworks (like MITRE ATT&CK) refer to the why behind an adversary's actions - their overall objectives and goals (B), such as espionage, financial gain, or disruption. Options A and C are implementation details (encryption choice, programming…

Threat Actor Attribution Techniques

Question

Identifying a threat actor's tactics involves understanding their:

Options

  • APreferred malware encryption algorithm
  • BOverall objectives and goals
  • CChoice of programming language
  • DSpecific vulnerabilities targeted

How the community answered

(21 responses)
  • A
    5% (1)
  • B
    90% (19)
  • D
    5% (1)

Explanation

Tactics in threat intelligence frameworks (like MITRE ATT&CK) refer to the why behind an adversary's actions - their overall objectives and goals (B), such as espionage, financial gain, or disruption. Options A and C are implementation details (encryption choice, programming language) that describe tools, not tactics. Option D describes specific technical targets, which maps to techniques or vulnerabilities exploited, not overarching tactics.

Memory tip: Think of the acronym TTPs - Tactics, Techniques, Procedures. Tactics = goals/objectives (the "why"), Techniques = how they achieve it (the "what"), Procedures = specific steps (the "how exactly"). The other options all describe lower-level details that fall under techniques or procedures, not tactics.

Topics

#threat actor objectives#threat actor tactics#threat attribution#attack planning

Community Discussion

No community discussion yet for this question.

Full 300-220 Practice