Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-220 Exam - Topic 2 Question 5 Discussion

Refer to the exhibit.An increase in company traffic is observed by the SOC team. After they investigate the spike, it is concluded that the increase is due to ongoing scanning activity. Further analysis reveals that an adversary used Nmap for OS fingerprinting. Which type of indicators used by the adversary sits highest on the Pyramid of Pain?
C) network/host artifacts
A) UDPs
B) port probes
D) IP addresses

Cisco 300-220 Exam - Topic 2 Question 5 Discussion

Actual exam question for Cisco's 300-220 exam
Question #: 5
Topic #: 2
[All 300-220 Questions]

Refer to the exhibit.

An increase in company traffic is observed by the SOC team. After they investigate the spike, it is concluded that the increase is due to ongoing scanning activity. Further analysis reveals that an adversary used Nmap for OS fingerprinting. Which type of indicators used by the adversary sits highest on the Pyramid of Pain?

Show Suggested Answer Hide Answer
Suggested Answer: C

The correct answer is Network/host artifacts. To understand why, it is important to map the observed attacker behavior to the Pyramid of Pain, a model that ranks indicators by how difficult they are for adversaries to change once detected.

In this scenario, the adversary is using Nmap OS fingerprinting, which involves sending carefully crafted packets and analyzing responses (TCP/IP stack behavior, TTL values, window sizes, flags, and timing characteristics). These behaviors leave behind network and host artifacts, such as distinctive scan patterns, abnormal TCP flag combinations, OS fingerprinting probes, and consistent tool-specific traffic signatures.

On the Pyramid of Pain:

IP addresses (D) sit at the very bottom. Attackers can trivially change IPs using VPNs, proxies, or botnets.

Port probes (B) and UDPs (A) represent low-level indicators that are also easy to modify. An attacker can change scan ports, protocols, or scan timing with minimal effort.

Network/host artifacts (C) sit significantly higher. These include tool-generated behaviors, protocol anomalies, OS fingerprinting patterns, and scan logic inherent to tools like Nmap. Changing these requires attackers to reconfigure tools, write custom scanners, or significantly alter their operational approach.

From a threat hunting and SOC maturity perspective, detecting and alerting on network and host artifacts forces attackers to expend more time and resources, increasing their operational cost. This aligns with the core objective of the Pyramid of Pain: maximize adversary pain by detecting behaviors, not easily replaceable indicators.

Professionally mature SOC teams focus on identifying scanning techniques (e.g., Nmap OS detection, TCP ACK probes, UDP probes) rather than blocking individual IPs. These detections are resilient, scalable, and effective against both commodity attackers and advanced adversaries.

In short, while IPs and ports are useful for short-term containment, network and host artifacts provide the highest-value indicators in this scenario, making C the correct answer.


Contribute your Thoughts:

0/2000 characters
Karan
19 days ago
Exactly! It's all about practical application.
upvoted 0 times
...
Alberta
24 days ago
I just hope we can apply this knowledge in real scenarios.
upvoted 0 times
...
Krissy
29 days ago
True, but they can still be part of the overall picture.
upvoted 0 times
...
Derrick
1 month ago
But aren't UDPs less significant in this context?
upvoted 0 times
...
Francisca
1 month ago
I lean towards network/host artifacts. They reveal more about the attack.
upvoted 0 times
...
Karan
1 month ago
I agree, but port probes seem more relevant to the scanning activity.
upvoted 0 times
...
Alberta
2 months ago
Definitely! I feel like IP addresses are the most identifiable.
upvoted 0 times
...
Krissy
2 months ago
This question is tricky. I think it's about understanding the Pyramid of Pain.
upvoted 0 times
...
Niesha
2 months ago
Surprised this is even a question! I thought everyone knew it’s about the port probes!
upvoted 0 times
...
Casandra
2 months ago
I agree with B) port probes. Makes sense for scanning activity.
upvoted 0 times
...
Gerald
2 months ago
Wait, are we sure it’s not C) network/host artifacts? Seems like a strong contender.
upvoted 0 times
...
Christiane
4 months ago
I think it’s actually D) IP addresses. They’re more identifiable.
upvoted 0 times
...
Odelia
4 months ago
Definitely B) port probes. They’re pretty basic but crucial.
upvoted 0 times
...
Britt
5 months ago
I’ve seen similar questions before, and I think UDPs are usually lower on the scale. I’m leaning towards port probes being the right answer, but I’m not completely convinced.
upvoted 0 times
...
Adria
5 months ago
This question seems familiar! I believe network/host artifacts are significant, but I’m not confident they sit at the top of the Pyramid of Pain.
upvoted 0 times
...
Coleen
5 months ago
I remember practicing a question about Nmap and its techniques. I feel like port probes might be a strong contender, but I can't recall if they rank higher than IP addresses.
upvoted 0 times
...
Derick
5 months ago
I think the highest indicators on the Pyramid of Pain are usually the ones that are harder to change, like IP addresses. But I'm not entirely sure.
upvoted 0 times
...

Save Cancel