300-215 exam dumps

300-215 practice question 161 of 229

Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-215 Question 161

Select 3

During a forensic investigation, you are tasked with analyzing threat intelligence artifacts received from Cisco SecureX Threat Response. The artifacts include IP addresses, domain names, file hashes, and TTPs (Tactics, Techniques, and Procedures). Based on these artifacts, how would you determine the likely threat actor profile?

  1. A

    Correlate the artifacts with known indicators of compromise (IOCs) and match them to profiles in a threat intelligence database.

  2. B

    Analyze the TTPs and map them to adversary behaviors outlined in the MITRE ATT&CK framework.

  3. C

    Ignore file hash information as it rarely contributes to identifying threat actor profiles.

  4. D

    Investigate the geographical origin of the IP addresses and domain registrations to infer potential attribution.

  5. E

    Use Cisco Umbrella to block the associated domains and conclude the investigation without further analysis.

Show answer and explanation

Correct answers: A, B, D

Explanation

To determine a threat actor profile, it is essential to analyze all available artifacts and correlate them with known intelligence. This includes leveraging IOCs, matching TTPs with frameworks like MITRE ATT&CK, and investigating infrastructure details such as geographical origins. These steps collectively help build a comprehensive understanding of the potential threat actor.

  • A. Correct.

    Correlating the artifacts with known IOCs in a threat intelligence database can provide insights into the specific threat actor or group responsible for the activity.

  • B. Correct.

    Mapping TTPs to adversary behaviors in the MITRE ATT&CK framework helps identify the techniques commonly associated with specific threat actors.

  • C. Incorrect.

    File hashes can help identify malware or tools used by a threat actor, making them useful in determining the profile. Ignoring them is not a best practice.

  • D. Correct.

    Geographical origin of IPs and domain registrations can give clues about the threat actor’s potential location or infrastructure.

  • E. Incorrect.

    Blocking domains with Cisco Umbrella is a mitigation step, not a method for determining the threat actor profile. It does not contribute to forensic attribution.

Timed practice exam

Take a 300-215 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam