Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-220 Exam - Topic 4 Question 13 Discussion

During an investigation, analysts observe that attackers consistently avoid PowerShell logging, disable AMSI, and prefer WMI for execution. Why is this information critical for attribution?
C) It reflects the attacker's operational preferences
A) It identifies the malware family used
B) It reveals the attacker's IP infrastructure
D) It confirms the exploit used for initial access

Cisco 300-220 Exam - Topic 4 Question 13 Discussion

Actual exam question for Cisco's 300-220 exam
Question #: 13
Topic #: 4
[All 300-220 Questions]

During an investigation, analysts observe that attackers consistently avoid PowerShell logging, disable AMSI, and prefer WMI for execution. Why is this information critical for attribution?

Show Suggested Answer Hide Answer
Suggested Answer: C

The correct answer is it reflects the attacker's operational preferences. Attribution relies on understanding how attackers operate, not just what tools they use.

Operational preferences---such as avoiding PowerShell logging, disabling AMSI, and favoring WMI---are behavioral signatures. These patterns often persist across campaigns and are documented in threat intelligence reports associated with specific adversaries.

Option A is incorrect because malware families change frequently. Option B is unreliable due to infrastructure rotation. Option D is unrelated to post-access tradecraft.

Professional attribution focuses on:

Execution methods

Defensive evasion choices

Tooling preferences

Workflow consistency

Mapping these behaviors to MITRE ATT&CK techniques enables analysts to compare findings against known threat actor profiles. This provides higher confidence attribution than artifact-based indicators.

Thus, option C is the correct answer.


Contribute your Thoughts:

0/2000 characters
Adell
2 days ago
Agreed, C makes sense. Their preferences tell us a lot.
upvoted 0 times
...
Cortney
7 days ago
I think it's C. It shows how the attacker operates.
upvoted 0 times
...
Ma
12 days ago
Not sure if it really helps with attribution though.
upvoted 0 times
...
Arthur
17 days ago
Disabling AMSI is a classic move for stealthy attacks.
upvoted 0 times
...
Viva
23 days ago
Wait, are they really avoiding PowerShell logging? That's surprising!
upvoted 0 times
...
Adolph
28 days ago
I think it shows their operational style, totally agree!
upvoted 0 times
...
Sophia
1 month ago
That's definitely a pattern in their tactics.
upvoted 0 times
...
Whitley
1 month ago
I vaguely recall something about how disabling AMSI can be a signature of certain groups, but I can't quite connect it to the options given.
upvoted 0 times
...
Marylou
1 month ago
I feel like the focus on PowerShell and WMI could really point to the attacker's preferences in tools, which makes me lean towards option C.
upvoted 0 times
...
Devora
2 months ago
This reminds me of a practice question about identifying malware families based on behavior. I think it might relate to option A, but I’m not completely confident.
upvoted 0 times
...
Trina
2 months ago
I remember studying how operational preferences can indicate the tactics of different threat actors, but I'm not sure if that's the main reason for attribution here.
upvoted 0 times
...

Save Cancel