100-160 Question 237
Single answerDuring a cybersecurity investigation, a company’s security team is attempting to determine the source of a ransomware attack. The team is analyzing server logs, identifying tools used by the attacker, and correlating timestamps of malicious activities with external threat intelligence reports. Which of the following best describes the processes being utilized in this scenario?
- A
Network monitoring
- B
Attack attribution
- C
Digital forensics
- D
Incident response planning
Show answer and explanation
Correct answer: B
Explanation
The security team is correlating evidence such as server logs, attack tools, and timestamps with external threat intelligence to determine the origin of a ransomware attack. This process is best described as attack attribution, which focuses on identifying the attacker or source of an attack using various investigative techniques.
- A. Incorrect.
Network monitoring focuses on observing and analyzing live network traffic to detect anomalies or threats. While useful, it does not describe the investigative processes in this scenario.
- B. Correct.
Attack attribution involves identifying the source or origin of an attack by analyzing evidence and correlating it with known threat intelligence, which aligns with the activities described in this scenario.
- C. Incorrect.
Digital forensics involves collecting, preserving, and analyzing digital evidence, which is a related process but not the primary focus of the scenario described.
- D. Incorrect.
Incident response planning involves creating strategies and procedures to handle cybersecurity incidents but does not describe the investigative processes being carried out in this scenario.