100-160 exam dumps

100-160 practice question 239 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 239

Select 3

A cybersecurity team is investigating a ransomware attack on their organization. During the digital forensics process, they collected system logs, network traffic data, and file metadata from the infected systems. Which of the following steps are essential to properly attribute the attack to a specific threat actor?

  1. A

    Analyze the collected data to identify patterns, such as IP addresses or file hashes, linked to known threat groups.

  2. B

    Immediately delete infected files to prevent further spread of ransomware within the network.

  3. C

    Cross-reference evidence with threat intelligence databases to identify similar tactics, techniques, and procedures (TTPs).

  4. D

    Ensure the chain of custody is maintained for all collected evidence to preserve its integrity.

  5. E

    Contact the threat actor directly to negotiate and confirm their identity.

Show answer and explanation

Correct answers: A, C, D

Explanation

Proper attack attribution requires analyzing forensic evidence, correlating it with known threat actor behaviors, and ensuring evidence integrity. These steps allow investigators to link the attack to specific threat actors while preserving the credibility of their findings. Other actions, such as deleting files or contacting threat actors, are either outside the scope of attribution or could compromise the investigation.

  • A. Correct.

    Analyzing data patterns, such as IP addresses or file hashes, can help identify connections to known threat actors or groups, which is critical for attack attribution.

  • B. Incorrect.

    Deleting infected files might prevent further spread but is not part of the attribution process and could destroy important forensic evidence.

  • C. Correct.

    Cross-referencing evidence with threat intelligence databases helps correlate the attack with known threat actor TTPs, a key step in attribution.

  • D. Correct.

    Maintaining the chain of custody ensures that evidence remains untampered and admissible for potential legal proceedings or further investigation.

  • E. Incorrect.

    Contacting the threat actor directly is not considered a best practice in digital forensics or attack attribution and could lead to further risks.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam