Refer to the exhibit.

An increase in company traffic is observed by the SOC team. After they investigate the spike, it is concluded that the increase is due to ongoing scanning activity. Further analysis reveals that an adversary used Nmap for OS fingerprinting. Which type of indicators used by the adversary sits highest on the Pyramid of Pain?
The correct answer is Network/host artifacts. To understand why, it is important to map the observed attacker behavior to the Pyramid of Pain, a model that ranks indicators by how difficult they are for adversaries to change once detected.
In this scenario, the adversary is using Nmap OS fingerprinting, which involves sending carefully crafted packets and analyzing responses (TCP/IP stack behavior, TTL values, window sizes, flags, and timing characteristics). These behaviors leave behind network and host artifacts, such as distinctive scan patterns, abnormal TCP flag combinations, OS fingerprinting probes, and consistent tool-specific traffic signatures.
On the Pyramid of Pain:
IP addresses (D) sit at the very bottom. Attackers can trivially change IPs using VPNs, proxies, or botnets.
Port probes (B) and UDPs (A) represent low-level indicators that are also easy to modify. An attacker can change scan ports, protocols, or scan timing with minimal effort.
Network/host artifacts (C) sit significantly higher. These include tool-generated behaviors, protocol anomalies, OS fingerprinting patterns, and scan logic inherent to tools like Nmap. Changing these requires attackers to reconfigure tools, write custom scanners, or significantly alter their operational approach.
From a threat hunting and SOC maturity perspective, detecting and alerting on network and host artifacts forces attackers to expend more time and resources, increasing their operational cost. This aligns with the core objective of the Pyramid of Pain: maximize adversary pain by detecting behaviors, not easily replaceable indicators.
Professionally mature SOC teams focus on identifying scanning techniques (e.g., Nmap OS detection, TCP ACK probes, UDP probes) rather than blocking individual IPs. These detections are resilient, scalable, and effective against both commodity attackers and advanced adversaries.
In short, while IPs and ports are useful for short-term containment, network and host artifacts provide the highest-value indicators in this scenario, making C the correct answer.
Karan
19 days agoAlberta
24 days agoKrissy
29 days agoDerrick
1 month agoFrancisca
1 month agoKaran
1 month agoAlberta
2 months agoKrissy
2 months agoNiesha
2 months agoCasandra
2 months agoGerald
2 months agoChristiane
4 months agoOdelia
4 months agoBritt
5 months agoAdria
5 months agoColeen
5 months agoDerick
5 months ago