Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-220 Exam - Topic 2 Question 1 Discussion

A mature SOC notices that several incidents over the past year involved attackers abusing legitimate administrative tools rather than deploying custom malware. Leadership asks the threat hunting team to improve detection coverage in a way that increases attacker cost rather than relying on easily replaceable indicators. Which detection strategy best aligns with this objective?
B) Correlating attacker behavior across multiple MITRE ATT&CK techniques
A) Blocking known malicious file hashes at the endpoint
C) Ingesting additional commercial threat intelligence feeds
D) Creating alerts for newly registered domains

Cisco 300-220 Exam - Topic 2 Question 1 Discussion

Actual exam question for Cisco's 300-220 exam
Question #: 1
Topic #: 2
[All 300-220 Questions]

A mature SOC notices that several incidents over the past year involved attackers abusing legitimate administrative tools rather than deploying custom malware. Leadership asks the threat hunting team to improve detection coverage in a way that increases attacker cost rather than relying on easily replaceable indicators. Which detection strategy best aligns with this objective?

Show Suggested Answer Hide Answer
Suggested Answer: B

The correct answer is correlating attacker behavior across multiple MITRE ATT&CK techniques. This approach focuses on behavioral detection, which is the cornerstone of effective threat hunting and advanced security operations.

Attackers who abuse legitimate administrative tools---often referred to as living-off-the-land techniques---intentionally avoid malware-based detections. File hashes, signatures, and known indicators provide minimal value because there may be no malicious files at all. Options A and D sit at the lowest levels of the Pyramid of Pain, making them easy for adversaries to evade.

By correlating behavior across multiple ATT&CK techniques---such as credential access, lateral movement, privilege escalation, and command execution---defenders detect how the attacker operates rather than what tools they use. This forces adversaries to fundamentally change tradecraft, which is costly, risky, and time-consuming.

Option C improves visibility but does not inherently raise attacker cost. Threat intelligence feeds are reactive and often lag behind active campaigns.

From a professional threat hunting perspective, correlating multiple low-signal behaviors into a high-confidence attack pattern is how mature SOCs detect stealthy intrusions. This method also supports scalable detection engineering, improved alert fidelity, and reduced false positives.

This strategy directly aligns with higher tiers of the Threat Hunting Maturity Model and the top of the Pyramid of Pain, making option B the correct answer.


Contribute your Thoughts:

0/2000 characters
Kanisha
29 days ago
I see your point. B really does align with increasing costs for attackers.
upvoted 0 times
...
Kindra
1 month ago
Exactly! We need to make it costly for them to adapt.
upvoted 0 times
...
Vallie
1 month ago
True, but attackers can easily change their tools. Behavior is key.
upvoted 0 times
...
Kanisha
1 month ago
But what about option A? Blocking known hashes seems straightforward.
upvoted 0 times
...
Kindra
2 months ago
Agreed! Correlating behaviors can reveal patterns that are harder to mimic.
upvoted 0 times
...
Vallie
2 months ago
I think option B is the best. It focuses on behavior, not just signatures.
upvoted 0 times
...
Peggie
2 months ago
C seems like a waste of resources in this scenario.
upvoted 0 times
...
Hester
2 months ago
Totally agree with B, it’s about understanding the tactics!
upvoted 0 times
...
Felton
2 months ago
Surprised they’re not considering D more seriously!
upvoted 0 times
...
Isreal
4 months ago
I think A is still useful, but not the best fit here.
upvoted 0 times
...
Rolf
4 months ago
B is definitely the way to go. Correlating behaviors is key!
upvoted 0 times
...
Weldon
5 months ago
Creating alerts for newly registered domains might help, but it feels like a reactive measure. I wonder if it really increases the cost for attackers as much as the other options.
upvoted 0 times
...
Val
5 months ago
I remember a practice question where we discussed the importance of understanding attacker behavior. I feel like option B aligns well with that concept.
upvoted 0 times
...
Princess
5 months ago
I'm not entirely sure, but blocking known malicious file hashes seems too simplistic for this scenario. Attackers can easily change their methods.
upvoted 0 times
...
Veronique
5 months ago
I think correlating attacker behavior across multiple MITRE ATT&CK techniques could be the right approach. It seems like it would give a broader view of tactics used.
upvoted 0 times
...

Save Cancel