300-220 · Question #47
Procedures of a given threat actor can include:
The correct answer is D. Their choice of antivirus evasion techniques. Procedures in the context of threat actor TTPs (Tactics, Techniques, and Procedures) refer to the specific, repeatable methods an attacker uses to accomplish their objectives - antivirus evasion techniques (D) fit precisely because they describe how an attacker executes a step…
Question
Procedures of a given threat actor can include:
Options
- ATheir preferred time of day for launching attacks
- BThe specific type of coffee they drink
- CThe brand of computers they use
- DTheir choice of antivirus evasion techniques
How the community answered
(52 responses)- A6% (3)
- B2% (1)
- C2% (1)
- D90% (47)
Explanation
Procedures in the context of threat actor TTPs (Tactics, Techniques, and Procedures) refer to the specific, repeatable methods an attacker uses to accomplish their objectives - antivirus evasion techniques (D) fit precisely because they describe how an attacker executes a step of their attack. Options A, B, and C are wrong because preferred attack timing is more of an operational habit than a procedure, coffee preferences and computer brand are personal/logistical details entirely unrelated to attack methodology, and none of these describe replicable technical actions. A helpful memory tip: think of Procedures as the "how-to steps" in an attacker's playbook - if it describes a technical action taken during an attack (like evading AV), it's a procedure; if it describes lifestyle or equipment preferences, it isn't.
Topics
Community Discussion
No community discussion yet for this question.