300-215 Question 160
Select 3During an incident investigation, you are tasked with analyzing threat intelligence data to determine the threat actor's profile. The threat intelligence report includes details such as the malware used, attack infrastructure, targeted industries, and TTPs (Tactics, Techniques, and Procedures). Based on these details, which combination of artifacts would most effectively help you identify the threat actor's profile?
- A
TTPs (Tactics, Techniques, and Procedures) documented in the MITRE ATT&CK framework
- B
IP addresses and domain names linked to the attack infrastructure
- C
List of compromised end-user credentials
- D
Industries or organizations targeted in previous attacks
- E
Details of the specific vulnerabilities exploited in the attack
Show answer and explanation
Correct answers: A, B, D
Explanation
To effectively determine the threat actor's profile, analysts should focus on artifacts that reveal consistent patterns, objectives, and behaviors. TTPs, attack infrastructure, and targeted industries provide critical insights into a threat actor's identity, motivations, and methods. These artifacts can be cross-referenced with threat intelligence databases to map the actor to known profiles. Other details, such as compromised credentials or specific vulnerabilities exploited, are more useful for immediate incident response but less effective for profiling the threat actor.
- A. Correct.
TTPs are critical in identifying threat actor profiles as they often remain consistent across multiple campaigns by the same actor. This information helps map the actor to known groups in threat intelligence databases.
- B. Correct.
IP addresses and domain names linked to the attack infrastructure can be cross-referenced with threat intelligence databases to identify patterns or previous associations with specific threat actors.
- C. Incorrect.
While compromised credentials are important for mitigating the current attack, they provide limited insight into the identity or motives of the threat actor and are not usually used for profiling.
- D. Correct.
Industries or organizations targeted can indicate the threat actor's motivations and objectives, which are key components of their profile (e.g., financial gain, espionage, or activism).
- E. Incorrect.
Details of specific vulnerabilities exploited are useful for patching and prevention but are not typically unique to a specific threat actor, as many actors exploit the same vulnerabilities.