300-215 Question 161
Select 3During a forensic investigation, you are tasked with analyzing threat intelligence artifacts received from Cisco SecureX Threat Response. The artifacts include IP addresses, domain names, file hashes, and TTPs (Tactics, Techniques, and Procedures). Based on these artifacts, how would you determine the likely threat actor profile?
- A
Correlate the artifacts with known indicators of compromise (IOCs) and match them to profiles in a threat intelligence database.
- B
Analyze the TTPs and map them to adversary behaviors outlined in the MITRE ATT&CK framework.
- C
Ignore file hash information as it rarely contributes to identifying threat actor profiles.
- D
Investigate the geographical origin of the IP addresses and domain registrations to infer potential attribution.
- E
Use Cisco Umbrella to block the associated domains and conclude the investigation without further analysis.
Show answer and explanation
Correct answers: A, B, D
Explanation
To determine a threat actor profile, it is essential to analyze all available artifacts and correlate them with known intelligence. This includes leveraging IOCs, matching TTPs with frameworks like MITRE ATT&CK, and investigating infrastructure details such as geographical origins. These steps collectively help build a comprehensive understanding of the potential threat actor.
- A. Correct.
Correlating the artifacts with known IOCs in a threat intelligence database can provide insights into the specific threat actor or group responsible for the activity.
- B. Correct.
Mapping TTPs to adversary behaviors in the MITRE ATT&CK framework helps identify the techniques commonly associated with specific threat actors.
- C. Incorrect.
File hashes can help identify malware or tools used by a threat actor, making them useful in determining the profile. Ignoring them is not a best practice.
- D. Correct.
Geographical origin of IPs and domain registrations can give clues about the threat actor’s potential location or infrastructure.
- E. Incorrect.
Blocking domains with Cisco Umbrella is a mitigation step, not a method for determining the threat actor profile. It does not contribute to forensic attribution.