nerdexam
Cisco

300-220 · Question #76

An attack's timeline can help distinguish between:

The correct answer is C. An authorized assessment and an unauthorized attack. Attack timelines are a key forensic tool for determining authorization: authorized assessments (penetration tests, red team exercises) follow pre-agreed schedules, scopes, and notification windows, while unauthorized attacks occur without any such agreement - making the…

Threat Hunting Techniques

Question

An attack's timeline can help distinguish between:

Options

  • AAn insider threat and an external attacker
  • BA brute force attack and a DDoS attack
  • CAn authorized assessment and an unauthorized attack
  • DThe use of AI and manual hacking techniques

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    10% (3)
  • C
    83% (25)
  • D
    3% (1)

Explanation

Attack timelines are a key forensic tool for determining authorization: authorized assessments (penetration tests, red team exercises) follow pre-agreed schedules, scopes, and notification windows, while unauthorized attacks occur without any such agreement - making the timeline a definitive distinguishing factor between the two, making C correct.

Why the distractors fail:

  • A - Timeline alone cannot reliably separate insiders from external attackers; both can act at any time of day, and attribution requires behavioral, access-log, and network evidence beyond just timing.
  • B - Brute force and DDoS attacks are distinguished by their nature (credential guessing vs. traffic flooding), not their timeline; both can be brief or prolonged.
  • D - AI-assisted and manual hacking often overlap in timing patterns; no reliable temporal signature separates them.

Memory tip: Think of a scheduled dentist appointment vs. someone breaking into the office after hours - the calendar and agreement is what makes one authorized and the other not. If it's on the schedule, it's authorized; if it's a surprise, it's an attack.

Topics

#timeline analysis#threat attribution#authorized vs unauthorized#incident investigation

Community Discussion

No community discussion yet for this question.

Full 300-220 Practice