100-160 exam dumps

100-160 practice question 243 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 243

Select 3

A security analyst is investigating a potential breach of a company's network. Using the Cyber Kill Chain framework, they determine that the attacker has successfully established command and control (C2) communication. The analyst needs to identify appropriate tactics, techniques, and procedures (TTP) using the MITRE ATT&CK Matrix, as well as ensure proper evidence handling for further investigation. What should the analyst prioritize to maintain the integrity of the investigation and identify the attacker's methods?

  1. A

    Document all evidence and maintain a strict chain of custody

  2. B

    Match the observed attacker behavior to MITRE ATT&CK tactics and techniques

  3. C

    Immediately delete all suspicious files to prevent further C2 communication

  4. D

    Capture volatile data, such as memory and active network connections, before shutting down affected systems

  5. E

    Focus solely on identifying the attacker's Diamond Model attributes (adversary, capability, infrastructure, victim)

Show answer and explanation

Correct answers: A, B, D

Explanation

During an investigation using frameworks like the Cyber Kill Chain and MITRE ATT&CK, the analyst must prioritize evidence preservation, mapping attacker techniques, and capturing volatile data to ensure a comprehensive understanding of the attack. Proper evidence handling, such as maintaining a chain of custody, ensures that the evidence remains valid for further analysis or legal proceedings. Avoid actions like deleting files prematurely, as they can compromise the investigation.

  • A. Correct.

    Maintaining a strict chain of custody is critical for preserving digital evidence and ensuring it is admissible in court or for internal investigation purposes.

  • B. Correct.

    Mapping attacker behavior to MITRE ATT&CK tactics and techniques helps the analyst identify the attacker's methods and goals, providing crucial insight into the attack.

  • C. Incorrect.

    Deleting suspicious files immediately could result in the loss of critical evidence needed for forensic analysis, making this an inappropriate action during an investigation.

  • D. Correct.

    Capturing volatile data ensures that critical evidence, such as memory and network connections, is preserved before it is lost due to system shutdown or other changes.

  • E. Incorrect.

    While the Diamond Model provides useful insights into the attacker's attributes, focusing solely on it neglects other important aspects of the investigation, such as evidence collection and mapping TTPs.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam