CompTIA CySA+ CS0-003 Attack Methodology Frameworks Practice Test

 

Objective 3.1 • 40 original questions

This CompTIA CySA+ CS0-003 practice test focuses on objective 3.1: attack methodology frameworks. All questions are original ExamSnap scenarios aligned to the official CS0-003 objective set; they are not copied from live CompTIA exam content. Review every option explanation to understand why a choice fits or does not fit the scenario. For broader exam preparation, review the CompTIA CySA+ CS0-003 Exam Dumps page.

Instructions: Select the best answer unless the question explicitly says Select TWO or Select THREE. Review the explanation and option review after answering.

Question 1

Adventure Works is designing a combined control. It must map an attacker activity focused on researching people, systems, domains, or technologies, and identify the attacker entity in the Diamond Model. Which TWO options are most appropriate? Assume no additional product-specific features are available beyond the concepts listed.

  1. Diamond Model capability
  2. Kill-chain delivery
  3. MITRE ATT&CK
  4. Kill-chain reconnaissance
  5. Diamond Model adversary

Correct answers: D, E

Why: Reconnaissance gathers target information before attempting access. It directly fits this scenario because the requirement is to map an attacker activity focused on researching people, systems, domains, or technologies. The adversary node represents the actor responsible for the intrusion activity. It directly fits this scenario because the requirement is to identify the attacker entity in the Diamond Model.

Option review:

A: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map an attacker activity focused on researching people, systems, domains, or technologies; identify the attacker entity in the Diamond Model.

B: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map an attacker activity focused on researching people, systems, domains, or technologies; identify the attacker entity in the Diamond Model.

C: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map an attacker activity focused on researching people, systems, domains, or technologies; identify the attacker entity in the Diamond Model.

D: Reconnaissance gathers target information before attempting access. It directly fits this scenario because the requirement is to map an attacker activity focused on researching people, systems, domains, or technologies.

E: The adversary node represents the actor responsible for the intrusion activity. It directly fits this scenario because the requirement is to identify the attacker entity in the Diamond Model.

Learning point: Use Kill-chain reconnaissance, Diamond Model adversary when the key requirement is to map an attacker activity focused on researching people, systems, domains, or technologies; identify the attacker entity in the Diamond Model.

Question 2

During an investigation at Wide World Importers, the immediate requirement is to map the stage where an attacker combines an exploit with a malicious payload. What should an incident coordinator select? The organization wants a vendor-neutral approach that can be explained during audit review.

  1. Kill-chain actions on objectives
  2. Kill-chain weaponization
  3. Kill-chain reconnaissance
  4. Diamond Model adversary
  5. MITRE ATT&CK

Correct answer: B

Why: Weaponization prepares exploit code and payloads for use against a target. It directly fits this scenario because the requirement is to map the stage where an attacker combines an exploit with a malicious payload.

Option review:

A: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where an attacker combines an exploit with a malicious payload.

B: Weaponization prepares exploit code and payloads for use against a target. It directly fits this scenario because the requirement is to map the stage where an attacker combines an exploit with a malicious payload.

C: Reconnaissance gathers target information before attempting access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where an attacker combines an exploit with a malicious payload.

D: The adversary node represents the actor responsible for the intrusion activity. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where an attacker combines an exploit with a malicious payload.

E: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where an attacker combines an exploit with a malicious payload.

Learning point: Use Kill-chain weaponization when the key requirement is to map the stage where an attacker combines an exploit with a malicious payload.

Question 3

Datum Fabrication is updating its security operations standard for a mixed Windows and Linux estate. Which option most directly helps the team map the stage where a malicious attachment or link is sent to the victim? Base the decision on the primary security requirement, not on implementation convenience.

  1. OSSTMM
  2. Kill-chain exploitation
  3. Diamond Model capability
  4. Kill-chain delivery
  5. Diamond Model adversary

Correct answer: D

Why: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. It directly fits this scenario because the requirement is to map the stage where a malicious attachment or link is sent to the victim.

Option review:

A: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a malicious attachment or link is sent to the victim.

B: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a malicious attachment or link is sent to the victim.

C: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a malicious attachment or link is sent to the victim.

D: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. It directly fits this scenario because the requirement is to map the stage where a malicious attachment or link is sent to the victim.

E: The adversary node represents the actor responsible for the intrusion activity. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a malicious attachment or link is sent to the victim.

Learning point: Use Kill-chain delivery when the key requirement is to map the stage where a malicious attachment or link is sent to the victim.

Question 4

For an e-commerce platform, the team must accomplish both of these goals: map the stage where a delivered exploit successfully abuses a vulnerability, and identify the malware or exploit used in the Diamond Model. Which TWO choices together provide the best match? The environment follows least privilege and preserves evidence where incident handling is involved.

  1. Kill-chain exploitation
  2. OWASP Testing Guide
  3. Kill-chain actions on objectives
  4. OSSTMM
  5. Diamond Model capability

Correct answers: A, E

Why: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. It directly fits this scenario because the requirement is to map the stage where a delivered exploit successfully abuses a vulnerability. Capability represents malware, exploits, tools, techniques, or skills used by the adversary. It directly fits this scenario because the requirement is to identify the malware or exploit used in the Diamond Model.

Option review:

A: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. It directly fits this scenario because the requirement is to map the stage where a delivered exploit successfully abuses a vulnerability.

B: The OWASP Testing Guide provides methodology and test ideas focused on web application security. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a delivered exploit successfully abuses a vulnerability; identify the malware or exploit used in the Diamond Model.

C: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a delivered exploit successfully abuses a vulnerability; identify the malware or exploit used in the Diamond Model.

D: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a delivered exploit successfully abuses a vulnerability; identify the malware or exploit used in the Diamond Model.

E: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. It directly fits this scenario because the requirement is to identify the malware or exploit used in the Diamond Model.

Learning point: Use Kill-chain exploitation, Diamond Model capability when the key requirement is to map the stage where a delivered exploit successfully abuses a vulnerability; identify the malware or exploit used in the Diamond Model.

Question 5

In a restricted research segment, a malware analyst must map the stage where malicious code is installed for continued access. Which approach is MOST appropriate? Use the choice that most directly addresses the stated evidence rather than a broader control.

  1. Diamond Model victim
  2. Kill-chain installation
  3. Kill-chain reconnaissance
  4. MITRE ATT&CK
  5. OWASP Testing Guide

Correct answer: B

Why: Installation establishes malware or another persistent foothold on the compromised system. It directly fits this scenario because the requirement is to map the stage where malicious code is installed for continued access.

Option review:

A: The victim node represents the targeted person, organization, system, or asset. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malicious code is installed for continued access.

B: Installation establishes malware or another persistent foothold on the compromised system. It directly fits this scenario because the requirement is to map the stage where malicious code is installed for continued access.

C: Reconnaissance gathers target information before attempting access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malicious code is installed for continued access.

D: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malicious code is installed for continued access.

E: The OWASP Testing Guide provides methodology and test ideas focused on web application security. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malicious code is installed for continued access.

Learning point: Use Kill-chain installation when the key requirement is to map the stage where malicious code is installed for continued access.

Question 6

During a security review, a SOC analyst must address two separate needs: map the stage where malware begins receiving remote instructions, and select a broad methodology for structured operational security testing. Select TWO. The team wants the most defensible analyst action before expanding the investigation.

  1. Kill-chain command and control
  2. Kill-chain installation
  3. OSSTMM
  4. MITRE ATT&CK
  5. Diamond Model adversary

Correct answers: A, C

Why: Command and control creates a communication channel through which the attacker can direct compromised systems. It directly fits this scenario because the requirement is to map the stage where malware begins receiving remote instructions. The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. It directly fits this scenario because the requirement is to select a broad methodology for structured operational security testing.

Option review:

A: Command and control creates a communication channel through which the attacker can direct compromised systems. It directly fits this scenario because the requirement is to map the stage where malware begins receiving remote instructions.

B: Installation establishes malware or another persistent foothold on the compromised system. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malware begins receiving remote instructions; select a broad methodology for structured operational security testing.

C: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. It directly fits this scenario because the requirement is to select a broad methodology for structured operational security testing.

D: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malware begins receiving remote instructions; select a broad methodology for structured operational security testing.

E: The adversary node represents the actor responsible for the intrusion activity. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malware begins receiving remote instructions; select a broad methodology for structured operational security testing.

Learning point: Use Kill-chain command and control, OSSTMM when the key requirement is to map the stage where malware begins receiving remote instructions; select a broad methodology for structured operational security testing.

Question 7

a threat hunter at Woodgrove Bank is comparing several approaches. The deciding requirement is to map the stage where the adversary exfiltrates data or disrupts business operations. Which option should be chosen? Select based on the scenario’s decisive constraint, not on which technology is newest.

  1. Kill-chain actions on objectives
  2. Diamond Model infrastructure
  3. Diamond Model capability
  4. Kill-chain command and control
  5. Kill-chain exploitation

Correct answer: A

Why: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. It directly fits this scenario because the requirement is to map the stage where the adversary exfiltrates data or disrupts business operations.

Option review:

A: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. It directly fits this scenario because the requirement is to map the stage where the adversary exfiltrates data or disrupts business operations.

B: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where the adversary exfiltrates data or disrupts business operations.

C: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where the adversary exfiltrates data or disrupts business operations.

D: Command and control creates a communication channel through which the attacker can direct compromised systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where the adversary exfiltrates data or disrupts business operations.

E: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where the adversary exfiltrates data or disrupts business operations.

Learning point: Use Kill-chain actions on objectives when the key requirement is to map the stage where the adversary exfiltrates data or disrupts business operations.

Question 8

While supporting a regulated customer-data environment, a risk analyst is asked to identify the attacker entity in the Diamond Model. Which concept or tool is the clearest match? Assume the activity is authorized and must follow normal enterprise change control.

  1. Diamond Model adversary
  2. Kill-chain actions on objectives
  3. Kill-chain exploitation
  4. Diamond Model victim
  5. Diamond Model capability

Correct answer: A

Why: The adversary node represents the actor responsible for the intrusion activity. It directly fits this scenario because the requirement is to identify the attacker entity in the Diamond Model.

Option review:

A: The adversary node represents the actor responsible for the intrusion activity. It directly fits this scenario because the requirement is to identify the attacker entity in the Diamond Model.

B: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the attacker entity in the Diamond Model.

C: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the attacker entity in the Diamond Model.

D: The victim node represents the targeted person, organization, system, or asset. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the attacker entity in the Diamond Model.

E: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the attacker entity in the Diamond Model.

Learning point: Use Diamond Model adversary when the key requirement is to identify the attacker entity in the Diamond Model.

Question 9

A new security procedure at Contoso Health must enable analysts to identify the target of the adversary in the Diamond Model. Which option is the BEST choice? Assume no additional product-specific features are available beyond the concepts listed.

  1. Diamond Model victim
  2. Diamond Model capability
  3. Diamond Model adversary
  4. Kill-chain installation
  5. MITRE ATT&CK

Correct answer: A

Why: The victim node represents the targeted person, organization, system, or asset. It directly fits this scenario because the requirement is to identify the target of the adversary in the Diamond Model.

Option review:

A: The victim node represents the targeted person, organization, system, or asset. It directly fits this scenario because the requirement is to identify the target of the adversary in the Diamond Model.

B: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the target of the adversary in the Diamond Model.

C: The adversary node represents the actor responsible for the intrusion activity. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the target of the adversary in the Diamond Model.

D: Installation establishes malware or another persistent foothold on the compromised system. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the target of the adversary in the Diamond Model.

E: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the target of the adversary in the Diamond Model.

Learning point: Use Diamond Model victim when the key requirement is to identify the target of the adversary in the Diamond Model.

Question 10

The primary objective for Blue Yonder Airlines is to identify attacker-controlled domains or servers in the Diamond Model. Which selection best satisfies that objective in an airline operations network? The organization wants a vendor-neutral approach that can be explained during audit review.

  1. Kill-chain installation
  2. Diamond Model infrastructure
  3. Kill-chain weaponization
  4. Diamond Model capability
  5. Kill-chain delivery

Correct answer: B

Why: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. It directly fits this scenario because the requirement is to identify attacker-controlled domains or servers in the Diamond Model.

Option review:

A: Installation establishes malware or another persistent foothold on the compromised system. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify attacker-controlled domains or servers in the Diamond Model.

B: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. It directly fits this scenario because the requirement is to identify attacker-controlled domains or servers in the Diamond Model.

C: Weaponization prepares exploit code and payloads for use against a target. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify attacker-controlled domains or servers in the Diamond Model.

D: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify attacker-controlled domains or servers in the Diamond Model.

E: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify attacker-controlled domains or servers in the Diamond Model.

Learning point: Use Diamond Model infrastructure when the key requirement is to identify attacker-controlled domains or servers in the Diamond Model.

Question 11

At Lucerne Publishing, a detection engineer needs to identify the malware or exploit used in the Diamond Model. Which option is the BEST fit for a remote-work environment? Base the decision on the primary security requirement, not on implementation convenience.

  1. Kill-chain weaponization
  2. Kill-chain command and control
  3. Kill-chain installation
  4. Diamond Model victim
  5. Diamond Model capability

Correct answer: E

Why: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. It directly fits this scenario because the requirement is to identify the malware or exploit used in the Diamond Model.

Option review:

A: Weaponization prepares exploit code and payloads for use against a target. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the malware or exploit used in the Diamond Model.

B: Command and control creates a communication channel through which the attacker can direct compromised systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the malware or exploit used in the Diamond Model.

C: Installation establishes malware or another persistent foothold on the compromised system. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the malware or exploit used in the Diamond Model.

D: The victim node represents the targeted person, organization, system, or asset. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the malware or exploit used in the Diamond Model.

E: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. It directly fits this scenario because the requirement is to identify the malware or exploit used in the Diamond Model.

Learning point: Use Diamond Model capability when the key requirement is to identify the malware or exploit used in the Diamond Model.

Question 12

During an investigation at Fabrikam Finance, the immediate requirement is to map observed behavior to standardized adversary techniques. What should a vulnerability analyst select? The environment follows least privilege and preserves evidence where incident handling is involved.

  1. Kill-chain delivery
  2. Kill-chain actions on objectives
  3. Kill-chain reconnaissance
  4. MITRE ATT&CK
  5. Kill-chain weaponization

Correct answer: D

Why: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. It directly fits this scenario because the requirement is to map observed behavior to standardized adversary techniques.

Option review:

A: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map observed behavior to standardized adversary techniques.

B: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map observed behavior to standardized adversary techniques.

C: Reconnaissance gathers target information before attempting access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map observed behavior to standardized adversary techniques.

D: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. It directly fits this scenario because the requirement is to map observed behavior to standardized adversary techniques.

E: Weaponization prepares exploit code and payloads for use against a target. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map observed behavior to standardized adversary techniques.

Learning point: Use MITRE ATT&CK when the key requirement is to map observed behavior to standardized adversary techniques.

Question 13

City Power Utilities is updating its security operations standard for a segmented industrial environment. Which option most directly helps the team select a broad methodology for structured operational security testing? Use the choice that most directly addresses the stated evidence rather than a broader control.

  1. Diamond Model victim
  2. Diamond Model adversary
  3. Kill-chain exploitation
  4. OSSTMM
  5. Diamond Model infrastructure

Correct answer: D

Why: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. It directly fits this scenario because the requirement is to select a broad methodology for structured operational security testing.

Option review:

A: The victim node represents the targeted person, organization, system, or asset. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a broad methodology for structured operational security testing.

B: The adversary node represents the actor responsible for the intrusion activity. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a broad methodology for structured operational security testing.

C: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a broad methodology for structured operational security testing.

D: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. It directly fits this scenario because the requirement is to select a broad methodology for structured operational security testing.

E: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a broad methodology for structured operational security testing.

Learning point: Use OSSTMM when the key requirement is to select a broad methodology for structured operational security testing.

Question 14

During a security review, a security consultant must address two separate needs: select a testing methodology specifically focused on web applications, and map the stage where the adversary exfiltrates data or disrupts business operations. Select TWO. The team wants the most defensible analyst action before expanding the investigation.

  1. Kill-chain delivery
  2. Kill-chain actions on objectives
  3. OWASP Testing Guide
  4. Kill-chain weaponization
  5. OSSTMM

Correct answers: B, C

Why: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. It directly fits this scenario because the requirement is to map the stage where the adversary exfiltrates data or disrupts business operations. The OWASP Testing Guide provides methodology and test ideas focused on web application security. It directly fits this scenario because the requirement is to select a testing methodology specifically focused on web applications.

Option review:

A: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a testing methodology specifically focused on web applications; map the stage where the adversary exfiltrates data or disrupts business operations.

B: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. It directly fits this scenario because the requirement is to map the stage where the adversary exfiltrates data or disrupts business operations.

C: The OWASP Testing Guide provides methodology and test ideas focused on web application security. It directly fits this scenario because the requirement is to select a testing methodology specifically focused on web applications.

D: Weaponization prepares exploit code and payloads for use against a target. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a testing methodology specifically focused on web applications; map the stage where the adversary exfiltrates data or disrupts business operations.

E: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a testing methodology specifically focused on web applications; map the stage where the adversary exfiltrates data or disrupts business operations.

Learning point: Use OWASP Testing Guide, Kill-chain actions on objectives when the key requirement is to select a testing methodology specifically focused on web applications; map the stage where the adversary exfiltrates data or disrupts business operations.

Question 15

At Northwind Traders, a security engineer has two simultaneous requirements: map an attacker activity focused on researching people, systems, domains, or technologies, and identify the attacker entity in the Diamond Model. Which TWO options should be selected? Select based on the scenario’s decisive constraint, not on which technology is newest.

  1. Kill-chain reconnaissance
  2. Diamond Model adversary
  3. Diamond Model infrastructure
  4. Kill-chain weaponization
  5. Kill-chain command and control

Correct answers: A, B

Why: Reconnaissance gathers target information before attempting access. It directly fits this scenario because the requirement is to map an attacker activity focused on researching people, systems, domains, or technologies. The adversary node represents the actor responsible for the intrusion activity. It directly fits this scenario because the requirement is to identify the attacker entity in the Diamond Model.

Option review:

A: Reconnaissance gathers target information before attempting access. It directly fits this scenario because the requirement is to map an attacker activity focused on researching people, systems, domains, or technologies.

B: The adversary node represents the actor responsible for the intrusion activity. It directly fits this scenario because the requirement is to identify the attacker entity in the Diamond Model.

C: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map an attacker activity focused on researching people, systems, domains, or technologies; identify the attacker entity in the Diamond Model.

D: Weaponization prepares exploit code and payloads for use against a target. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map an attacker activity focused on researching people, systems, domains, or technologies; identify the attacker entity in the Diamond Model.

E: Command and control creates a communication channel through which the attacker can direct compromised systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map an attacker activity focused on researching people, systems, domains, or technologies; identify the attacker entity in the Diamond Model.

Learning point: Use Kill-chain reconnaissance, Diamond Model adversary when the key requirement is to map an attacker activity focused on researching people, systems, domains, or technologies; identify the attacker entity in the Diamond Model.

Question 16

A review at Alpine Ski House finds a gap: the team cannot reliably map the stage where an attacker combines an exploit with a malicious payload. Which option best closes that gap? Assume the activity is authorized and must follow normal enterprise change control.

  1. Kill-chain command and control
  2. Kill-chain weaponization
  3. Kill-chain actions on objectives
  4. Kill-chain exploitation
  5. Diamond Model victim

Correct answer: B

Why: Weaponization prepares exploit code and payloads for use against a target. It directly fits this scenario because the requirement is to map the stage where an attacker combines an exploit with a malicious payload.

Option review:

A: Command and control creates a communication channel through which the attacker can direct compromised systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where an attacker combines an exploit with a malicious payload.

B: Weaponization prepares exploit code and payloads for use against a target. It directly fits this scenario because the requirement is to map the stage where an attacker combines an exploit with a malicious payload.

C: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where an attacker combines an exploit with a malicious payload.

D: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where an attacker combines an exploit with a malicious payload.

E: The victim node represents the targeted person, organization, system, or asset. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where an attacker combines an exploit with a malicious payload.

Learning point: Use Kill-chain weaponization when the key requirement is to map the stage where an attacker combines an exploit with a malicious payload.

Question 17

a systems security analyst at Coho Winery is comparing several approaches. The deciding requirement is to map the stage where a malicious attachment or link is sent to the victim. Which option should be chosen? Assume no additional product-specific features are available beyond the concepts listed.

  1. Kill-chain delivery
  2. Diamond Model victim
  3. Diamond Model infrastructure
  4. Kill-chain installation
  5. Kill-chain command and control

Correct answer: A

Why: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. It directly fits this scenario because the requirement is to map the stage where a malicious attachment or link is sent to the victim.

Option review:

A: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. It directly fits this scenario because the requirement is to map the stage where a malicious attachment or link is sent to the victim.

B: The victim node represents the targeted person, organization, system, or asset. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a malicious attachment or link is sent to the victim.

C: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a malicious attachment or link is sent to the victim.

D: Installation establishes malware or another persistent foothold on the compromised system. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a malicious attachment or link is sent to the victim.

E: Command and control creates a communication channel through which the attacker can direct compromised systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a malicious attachment or link is sent to the victim.

Learning point: Use Kill-chain delivery when the key requirement is to map the stage where a malicious attachment or link is sent to the victim.

Question 18

During a security review, an incident responder must address two separate needs: map the stage where a delivered exploit successfully abuses a vulnerability, and identify the malware or exploit used in the Diamond Model. Select TWO. The organization wants a vendor-neutral approach that can be explained during audit review.

  1. Kill-chain exploitation
  2. Kill-chain command and control
  3. MITRE ATT&CK
  4. OWASP Testing Guide
  5. Diamond Model capability

Correct answers: A, E

Why: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. It directly fits this scenario because the requirement is to map the stage where a delivered exploit successfully abuses a vulnerability. Capability represents malware, exploits, tools, techniques, or skills used by the adversary. It directly fits this scenario because the requirement is to identify the malware or exploit used in the Diamond Model.

Option review:

A: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. It directly fits this scenario because the requirement is to map the stage where a delivered exploit successfully abuses a vulnerability.

B: Command and control creates a communication channel through which the attacker can direct compromised systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a delivered exploit successfully abuses a vulnerability; identify the malware or exploit used in the Diamond Model.

C: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a delivered exploit successfully abuses a vulnerability; identify the malware or exploit used in the Diamond Model.

D: The OWASP Testing Guide provides methodology and test ideas focused on web application security. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a delivered exploit successfully abuses a vulnerability; identify the malware or exploit used in the Diamond Model.

E: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. It directly fits this scenario because the requirement is to identify the malware or exploit used in the Diamond Model.

Learning point: Use Kill-chain exploitation, Diamond Model capability when the key requirement is to map the stage where a delivered exploit successfully abuses a vulnerability; identify the malware or exploit used in the Diamond Model.

Question 19

At Fourth Coffee, a security administrator has two simultaneous requirements: map the stage where malicious code is installed for continued access, and map observed behavior to standardized adversary techniques. Which TWO options should be selected? Base the decision on the primary security requirement, not on implementation convenience.

  1. Kill-chain delivery
  2. Kill-chain actions on objectives
  3. Kill-chain installation
  4. Diamond Model infrastructure
  5. MITRE ATT&CK

Correct answers: C, E

Why: Installation establishes malware or another persistent foothold on the compromised system. It directly fits this scenario because the requirement is to map the stage where malicious code is installed for continued access. MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. It directly fits this scenario because the requirement is to map observed behavior to standardized adversary techniques.

Option review:

A: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malicious code is installed for continued access; map observed behavior to standardized adversary techniques.

B: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malicious code is installed for continued access; map observed behavior to standardized adversary techniques.

C: Installation establishes malware or another persistent foothold on the compromised system. It directly fits this scenario because the requirement is to map the stage where malicious code is installed for continued access.

D: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malicious code is installed for continued access; map observed behavior to standardized adversary techniques.

E: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. It directly fits this scenario because the requirement is to map observed behavior to standardized adversary techniques.

Learning point: Use Kill-chain installation, MITRE ATT&CK when the key requirement is to map the stage where malicious code is installed for continued access; map observed behavior to standardized adversary techniques.

Question 20

For a customer-facing messaging service, the team must accomplish both of these goals: map the stage where malware begins receiving remote instructions, and select a broad methodology for structured operational security testing. Which TWO choices together provide the best match? The environment follows least privilege and preserves evidence where incident handling is involved.

  1. OWASP Testing Guide
  2. OSSTMM
  3. Diamond Model victim
  4. Kill-chain command and control
  5. Diamond Model capability

Correct answers: B, D

Why: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. It directly fits this scenario because the requirement is to select a broad methodology for structured operational security testing. Command and control creates a communication channel through which the attacker can direct compromised systems. It directly fits this scenario because the requirement is to map the stage where malware begins receiving remote instructions.

Option review:

A: The OWASP Testing Guide provides methodology and test ideas focused on web application security. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malware begins receiving remote instructions; select a broad methodology for structured operational security testing.

B: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. It directly fits this scenario because the requirement is to select a broad methodology for structured operational security testing.

C: The victim node represents the targeted person, organization, system, or asset. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malware begins receiving remote instructions; select a broad methodology for structured operational security testing.

D: Command and control creates a communication channel through which the attacker can direct compromised systems. It directly fits this scenario because the requirement is to map the stage where malware begins receiving remote instructions.

E: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malware begins receiving remote instructions; select a broad methodology for structured operational security testing.

Learning point: Use Kill-chain command and control, OSSTMM when the key requirement is to map the stage where malware begins receiving remote instructions; select a broad methodology for structured operational security testing.

Question 21

At Adventure Works, a blue-team analyst needs to map the stage where the adversary exfiltrates data or disrupts business operations. Which option is the BEST fit for a hybrid-cloud workload? Use the choice that most directly addresses the stated evidence rather than a broader control.

  1. Kill-chain installation
  2. Diamond Model infrastructure
  3. Kill-chain reconnaissance
  4. Kill-chain actions on objectives
  5. Diamond Model adversary

Correct answer: D

Why: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. It directly fits this scenario because the requirement is to map the stage where the adversary exfiltrates data or disrupts business operations.

Option review:

A: Installation establishes malware or another persistent foothold on the compromised system. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where the adversary exfiltrates data or disrupts business operations.

B: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where the adversary exfiltrates data or disrupts business operations.

C: Reconnaissance gathers target information before attempting access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where the adversary exfiltrates data or disrupts business operations.

D: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. It directly fits this scenario because the requirement is to map the stage where the adversary exfiltrates data or disrupts business operations.

E: The adversary node represents the actor responsible for the intrusion activity. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where the adversary exfiltrates data or disrupts business operations.

Learning point: Use Kill-chain actions on objectives when the key requirement is to map the stage where the adversary exfiltrates data or disrupts business operations.

Question 22

During an investigation at Wide World Importers, the immediate requirement is to identify the attacker entity in the Diamond Model. What should an incident coordinator select? The team wants the most defensible analyst action before expanding the investigation.

  1. OSSTMM
  2. Diamond Model capability
  3. Diamond Model adversary
  4. OWASP Testing Guide
  5. Kill-chain reconnaissance

Correct answer: C

Why: The adversary node represents the actor responsible for the intrusion activity. It directly fits this scenario because the requirement is to identify the attacker entity in the Diamond Model.

Option review:

A: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the attacker entity in the Diamond Model.

B: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the attacker entity in the Diamond Model.

C: The adversary node represents the actor responsible for the intrusion activity. It directly fits this scenario because the requirement is to identify the attacker entity in the Diamond Model.

D: The OWASP Testing Guide provides methodology and test ideas focused on web application security. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the attacker entity in the Diamond Model.

E: Reconnaissance gathers target information before attempting access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the attacker entity in the Diamond Model.

Learning point: Use Diamond Model adversary when the key requirement is to identify the attacker entity in the Diamond Model.

Question 23

Datum Fabrication is updating its security operations standard for a mixed Windows and Linux estate. Which option most directly helps the team identify the target of the adversary in the Diamond Model? Select based on the scenario’s decisive constraint, not on which technology is newest.

  1. Kill-chain actions on objectives
  2. Diamond Model victim
  3. Diamond Model capability
  4. Kill-chain delivery
  5. Diamond Model adversary

Correct answer: B

Why: The victim node represents the targeted person, organization, system, or asset. It directly fits this scenario because the requirement is to identify the target of the adversary in the Diamond Model.

Option review:

A: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the target of the adversary in the Diamond Model.

B: The victim node represents the targeted person, organization, system, or asset. It directly fits this scenario because the requirement is to identify the target of the adversary in the Diamond Model.

C: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the target of the adversary in the Diamond Model.

D: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the target of the adversary in the Diamond Model.

E: The adversary node represents the actor responsible for the intrusion activity. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the target of the adversary in the Diamond Model.

Learning point: Use Diamond Model victim when the key requirement is to identify the target of the adversary in the Diamond Model.

Question 24

A ticket at Tailspin Toys asks a SOC lead to identify attacker-controlled domains or servers in the Diamond Model. Which choice addresses the requirement most directly? Assume the activity is authorized and must follow normal enterprise change control.

  1. Kill-chain installation
  2. Diamond Model infrastructure
  3. MITRE ATT&CK
  4. Diamond Model victim
  5. Kill-chain delivery

Correct answer: B

Why: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. It directly fits this scenario because the requirement is to identify attacker-controlled domains or servers in the Diamond Model.

Option review:

A: Installation establishes malware or another persistent foothold on the compromised system. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify attacker-controlled domains or servers in the Diamond Model.

B: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. It directly fits this scenario because the requirement is to identify attacker-controlled domains or servers in the Diamond Model.

C: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify attacker-controlled domains or servers in the Diamond Model.

D: The victim node represents the targeted person, organization, system, or asset. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify attacker-controlled domains or servers in the Diamond Model.

E: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify attacker-controlled domains or servers in the Diamond Model.

Learning point: Use Diamond Model infrastructure when the key requirement is to identify attacker-controlled domains or servers in the Diamond Model.

Question 25

At Proseware Research, the response plan has three distinct requirements: identify the malware or exploit used in the Diamond Model; map an attacker activity focused on researching people, systems, domains, or technologies; and map the stage where malicious code is installed for continued access. Which THREE options should be selected? Assume no additional product-specific features are available beyond the concepts listed.

  1. Kill-chain exploitation
  2. Kill-chain reconnaissance
  3. Kill-chain installation
  4. OSSTMM
  5. Diamond Model capability

Correct answers: B, C, E

Why: Reconnaissance gathers target information before attempting access. It directly fits this scenario because the requirement is to map an attacker activity focused on researching people, systems, domains, or technologies. Installation establishes malware or another persistent foothold on the compromised system. It directly fits this scenario because the requirement is to map the stage where malicious code is installed for continued access. Capability represents malware, exploits, tools, techniques, or skills used by the adversary. It directly fits this scenario because the requirement is to identify the malware or exploit used in the Diamond Model.

Option review:

A: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the malware or exploit used in the Diamond Model; map an attacker activity focused on researching people, systems, domains, or technologies; map the stage where malicious code is installed for continued access.

B: Reconnaissance gathers target information before attempting access. It directly fits this scenario because the requirement is to map an attacker activity focused on researching people, systems, domains, or technologies.

C: Installation establishes malware or another persistent foothold on the compromised system. It directly fits this scenario because the requirement is to map the stage where malicious code is installed for continued access.

D: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the malware or exploit used in the Diamond Model; map an attacker activity focused on researching people, systems, domains, or technologies; map the stage where malicious code is installed for continued access.

E: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. It directly fits this scenario because the requirement is to identify the malware or exploit used in the Diamond Model.

Learning point: Use Diamond Model capability, Kill-chain reconnaissance, Kill-chain installation when the key requirement is to identify the malware or exploit used in the Diamond Model; map an attacker activity focused on researching people, systems, domains, or technologies; map the stage where malicious code is installed for continued access.

Question 26

A review at Wingtip Services finds a gap: the team cannot reliably map observed behavior to standardized adversary techniques. Which option best closes that gap? The organization wants a vendor-neutral approach that can be explained during audit review.

  1. Diamond Model infrastructure
  2. Kill-chain command and control
  3. MITRE ATT&CK
  4. Diamond Model adversary
  5. Kill-chain installation

Correct answer: C

Why: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. It directly fits this scenario because the requirement is to map observed behavior to standardized adversary techniques.

Option review:

A: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map observed behavior to standardized adversary techniques.

B: Command and control creates a communication channel through which the attacker can direct compromised systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map observed behavior to standardized adversary techniques.

C: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. It directly fits this scenario because the requirement is to map observed behavior to standardized adversary techniques.

D: The adversary node represents the actor responsible for the intrusion activity. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map observed behavior to standardized adversary techniques.

E: Installation establishes malware or another persistent foothold on the compromised system. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map observed behavior to standardized adversary techniques.

Learning point: Use MITRE ATT&CK when the key requirement is to map observed behavior to standardized adversary techniques.

Question 27

a threat hunter at Woodgrove Bank is comparing several approaches. The deciding requirement is to select a broad methodology for structured operational security testing. Which option should be chosen? Base the decision on the primary security requirement, not on implementation convenience.

  1. Kill-chain actions on objectives
  2. Kill-chain exploitation
  3. OSSTMM
  4. Diamond Model infrastructure
  5. Diamond Model victim

Correct answer: C

Why: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. It directly fits this scenario because the requirement is to select a broad methodology for structured operational security testing.

Option review:

A: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a broad methodology for structured operational security testing.

B: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a broad methodology for structured operational security testing.

C: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. It directly fits this scenario because the requirement is to select a broad methodology for structured operational security testing.

D: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a broad methodology for structured operational security testing.

E: The victim node represents the targeted person, organization, system, or asset. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a broad methodology for structured operational security testing.

Learning point: Use OSSTMM when the key requirement is to select a broad methodology for structured operational security testing.

Question 28

While supporting a regulated customer-data environment, a risk analyst is asked to select a testing methodology specifically focused on web applications. Which concept or tool is the clearest match? The environment follows least privilege and preserves evidence where incident handling is involved.

  1. OWASP Testing Guide
  2. Kill-chain exploitation
  3. MITRE ATT&CK
  4. Diamond Model capability
  5. Diamond Model infrastructure

Correct answer: A

Why: The OWASP Testing Guide provides methodology and test ideas focused on web application security. It directly fits this scenario because the requirement is to select a testing methodology specifically focused on web applications.

Option review:

A: The OWASP Testing Guide provides methodology and test ideas focused on web application security. It directly fits this scenario because the requirement is to select a testing methodology specifically focused on web applications.

B: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a testing methodology specifically focused on web applications.

C: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a testing methodology specifically focused on web applications.

D: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a testing methodology specifically focused on web applications.

E: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a testing methodology specifically focused on web applications.

Learning point: Use OWASP Testing Guide when the key requirement is to select a testing methodology specifically focused on web applications.

Question 29

An audit follow-up for a customer-facing service records that the investigation has already ruled out routine administrative activity. To close the finding, the team must map an attacker activity focused on researching people, systems, domains, or technologies; and identify the attacker entity in the Diamond Model. Which option should the analyst recommend?

  1. MITRE ATT&CK
  2. Diamond Model adversary
  3. Kill-chain command and control
  4. OSSTMM
  5. Kill-chain reconnaissance

Correct answers: B, E

Why: The adversary node represents the actor responsible for the intrusion activity. It directly fits this scenario because the requirement is to identify the attacker entity in the Diamond Model. Reconnaissance gathers target information before attempting access. It directly fits this scenario because the requirement is to map an attacker activity focused on researching people, systems, domains, or technologies.

Option review:

A: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map an attacker activity focused on researching people, systems, domains, or technologies; identify the attacker entity in the Diamond Model.

B: The adversary node represents the actor responsible for the intrusion activity. It directly fits this scenario because the requirement is to identify the attacker entity in the Diamond Model.

C: Command and control creates a communication channel through which the attacker can direct compromised systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map an attacker activity focused on researching people, systems, domains, or technologies; identify the attacker entity in the Diamond Model.

D: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map an attacker activity focused on researching people, systems, domains, or technologies; identify the attacker entity in the Diamond Model.

E: Reconnaissance gathers target information before attempting access. It directly fits this scenario because the requirement is to map an attacker activity focused on researching people, systems, domains, or technologies.

Learning point: Use Kill-chain reconnaissance, Diamond Model adversary when the key requirement is to map an attacker activity focused on researching people, systems, domains, or technologies; identify the attacker entity in the Diamond Model.

Question 30

The primary objective for Blue Yonder Airlines is to map the stage where an attacker combines an exploit with a malicious payload. Which selection best satisfies that objective in an airline operations network? The team wants the most defensible analyst action before expanding the investigation.

  1. Kill-chain actions on objectives
  2. Kill-chain installation
  3. Diamond Model capability
  4. Kill-chain weaponization
  5. OSSTMM

Correct answer: D

Why: Weaponization prepares exploit code and payloads for use against a target. It directly fits this scenario because the requirement is to map the stage where an attacker combines an exploit with a malicious payload.

Option review:

A: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where an attacker combines an exploit with a malicious payload.

B: Installation establishes malware or another persistent foothold on the compromised system. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where an attacker combines an exploit with a malicious payload.

C: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where an attacker combines an exploit with a malicious payload.

D: Weaponization prepares exploit code and payloads for use against a target. It directly fits this scenario because the requirement is to map the stage where an attacker combines an exploit with a malicious payload.

E: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where an attacker combines an exploit with a malicious payload.

Learning point: Use Kill-chain weaponization when the key requirement is to map the stage where an attacker combines an exploit with a malicious payload.

Question 31

At Lucerne Publishing, a detection engineer needs to map the stage where a malicious attachment or link is sent to the victim. Which option is the BEST fit for a remote-work environment? Select based on the scenario’s decisive constraint, not on which technology is newest.

  1. Diamond Model adversary
  2. MITRE ATT&CK
  3. Kill-chain actions on objectives
  4. Kill-chain delivery
  5. Diamond Model victim

Correct answer: D

Why: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. It directly fits this scenario because the requirement is to map the stage where a malicious attachment or link is sent to the victim.

Option review:

A: The adversary node represents the actor responsible for the intrusion activity. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a malicious attachment or link is sent to the victim.

B: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a malicious attachment or link is sent to the victim.

C: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a malicious attachment or link is sent to the victim.

D: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. It directly fits this scenario because the requirement is to map the stage where a malicious attachment or link is sent to the victim.

E: The victim node represents the targeted person, organization, system, or asset. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a malicious attachment or link is sent to the victim.

Learning point: Use Kill-chain delivery when the key requirement is to map the stage where a malicious attachment or link is sent to the victim.

Question 32

In a research enclave, the evidence has been normalized and timestamps are trustworthy. The team has already ruled out unrelated controls and now must map the stage where a delivered exploit successfully abuses a vulnerability; and identify the malware or exploit used in the Diamond Model. Which choice is most defensible?

  1. Kill-chain reconnaissance
  2. Diamond Model capability
  3. Diamond Model adversary
  4. Diamond Model victim
  5. Kill-chain exploitation

Correct answers: B, E

Why: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. It directly fits this scenario because the requirement is to identify the malware or exploit used in the Diamond Model. Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. It directly fits this scenario because the requirement is to map the stage where a delivered exploit successfully abuses a vulnerability.

Option review:

A: Reconnaissance gathers target information before attempting access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a delivered exploit successfully abuses a vulnerability; identify the malware or exploit used in the Diamond Model.

B: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. It directly fits this scenario because the requirement is to identify the malware or exploit used in the Diamond Model.

C: The adversary node represents the actor responsible for the intrusion activity. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a delivered exploit successfully abuses a vulnerability; identify the malware or exploit used in the Diamond Model.

D: The victim node represents the targeted person, organization, system, or asset. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a delivered exploit successfully abuses a vulnerability; identify the malware or exploit used in the Diamond Model.

E: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. It directly fits this scenario because the requirement is to map the stage where a delivered exploit successfully abuses a vulnerability.

Learning point: Use Kill-chain exploitation, Diamond Model capability when the key requirement is to map the stage where a delivered exploit successfully abuses a vulnerability; identify the malware or exploit used in the Diamond Model.

Question 33

City Power Utilities is designing a combined control. It must map the stage where malicious code is installed for continued access, and map observed behavior to standardized adversary techniques. Which TWO options are most appropriate? Assume no additional product-specific features are available beyond the concepts listed.

  1. MITRE ATT&CK
  2. Kill-chain reconnaissance
  3. Diamond Model adversary
  4. Diamond Model victim
  5. Kill-chain installation

Correct answers: A, E

Why: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. It directly fits this scenario because the requirement is to map observed behavior to standardized adversary techniques. Installation establishes malware or another persistent foothold on the compromised system. It directly fits this scenario because the requirement is to map the stage where malicious code is installed for continued access.

Option review:

A: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. It directly fits this scenario because the requirement is to map observed behavior to standardized adversary techniques.

B: Reconnaissance gathers target information before attempting access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malicious code is installed for continued access; map observed behavior to standardized adversary techniques.

C: The adversary node represents the actor responsible for the intrusion activity. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malicious code is installed for continued access; map observed behavior to standardized adversary techniques.

D: The victim node represents the targeted person, organization, system, or asset. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malicious code is installed for continued access; map observed behavior to standardized adversary techniques.

E: Installation establishes malware or another persistent foothold on the compromised system. It directly fits this scenario because the requirement is to map the stage where malicious code is installed for continued access.

Learning point: Use Kill-chain installation, MITRE ATT&CK when the key requirement is to map the stage where malicious code is installed for continued access; map observed behavior to standardized adversary techniques.

Question 34

A ticket at A. Datum Logistics asks a security consultant to map the stage where malware begins receiving remote instructions. Which choice addresses the requirement most directly? The organization wants a vendor-neutral approach that can be explained during audit review.

  1. Kill-chain installation
  2. OWASP Testing Guide
  3. Kill-chain command and control
  4. Kill-chain weaponization
  5. Diamond Model infrastructure

Correct answer: C

Why: Command and control creates a communication channel through which the attacker can direct compromised systems. It directly fits this scenario because the requirement is to map the stage where malware begins receiving remote instructions.

Option review:

A: Installation establishes malware or another persistent foothold on the compromised system. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malware begins receiving remote instructions.

B: The OWASP Testing Guide provides methodology and test ideas focused on web application security. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malware begins receiving remote instructions.

C: Command and control creates a communication channel through which the attacker can direct compromised systems. It directly fits this scenario because the requirement is to map the stage where malware begins receiving remote instructions.

D: Weaponization prepares exploit code and payloads for use against a target. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malware begins receiving remote instructions.

E: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malware begins receiving remote instructions.

Learning point: Use Kill-chain command and control when the key requirement is to map the stage where malware begins receiving remote instructions.

Question 35

In a regional distribution network, a security engineer must map the stage where the adversary exfiltrates data or disrupts business operations. Which approach is MOST appropriate? Base the decision on the primary security requirement, not on implementation convenience.

  1. Diamond Model infrastructure
  2. Diamond Model capability
  3. Kill-chain actions on objectives
  4. Kill-chain installation
  5. Kill-chain delivery

Correct answer: C

Why: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. It directly fits this scenario because the requirement is to map the stage where the adversary exfiltrates data or disrupts business operations.

Option review:

A: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where the adversary exfiltrates data or disrupts business operations.

B: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where the adversary exfiltrates data or disrupts business operations.

C: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. It directly fits this scenario because the requirement is to map the stage where the adversary exfiltrates data or disrupts business operations.

D: Installation establishes malware or another persistent foothold on the compromised system. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where the adversary exfiltrates data or disrupts business operations.

E: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where the adversary exfiltrates data or disrupts business operations.

Learning point: Use Kill-chain actions on objectives when the key requirement is to map the stage where the adversary exfiltrates data or disrupts business operations.

Question 36

For a SaaS-heavy business, a cloud security analyst must satisfy all three needs: identify the attacker entity in the Diamond Model; map observed behavior to standardized adversary techniques; and map the stage where an attacker combines an exploit with a malicious payload. Select THREE. The environment follows least privilege and preserves evidence where incident handling is involved.

  1. Diamond Model adversary
  2. Kill-chain delivery
  3. Diamond Model capability
  4. MITRE ATT&CK
  5. Kill-chain weaponization

Correct answers: A, D, E

Why: The adversary node represents the actor responsible for the intrusion activity. It directly fits this scenario because the requirement is to identify the attacker entity in the Diamond Model. MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. It directly fits this scenario because the requirement is to map observed behavior to standardized adversary techniques. Weaponization prepares exploit code and payloads for use against a target. It directly fits this scenario because the requirement is to map the stage where an attacker combines an exploit with a malicious payload.

Option review:

A: The adversary node represents the actor responsible for the intrusion activity. It directly fits this scenario because the requirement is to identify the attacker entity in the Diamond Model.

B: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the attacker entity in the Diamond Model; map observed behavior to standardized adversary techniques; map the stage where an attacker combines an exploit with a malicious payload.

C: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the attacker entity in the Diamond Model; map observed behavior to standardized adversary techniques; map the stage where an attacker combines an exploit with a malicious payload.

D: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. It directly fits this scenario because the requirement is to map observed behavior to standardized adversary techniques.

E: Weaponization prepares exploit code and payloads for use against a target. It directly fits this scenario because the requirement is to map the stage where an attacker combines an exploit with a malicious payload.

Learning point: Use Diamond Model adversary, MITRE ATT&CK, Kill-chain weaponization when the key requirement is to identify the attacker entity in the Diamond Model; map observed behavior to standardized adversary techniques; map the stage where an attacker combines an exploit with a malicious payload.

Question 37

a systems security analyst at Coho Winery is comparing several approaches. The deciding requirement is to identify the target of the adversary in the Diamond Model. Which option should be chosen? Use the choice that most directly addresses the stated evidence rather than a broader control.

  1. Kill-chain installation
  2. Diamond Model victim
  3. Kill-chain actions on objectives
  4. MITRE ATT&CK
  5. Kill-chain exploitation

Correct answer: B

Why: The victim node represents the targeted person, organization, system, or asset. It directly fits this scenario because the requirement is to identify the target of the adversary in the Diamond Model.

Option review:

A: Installation establishes malware or another persistent foothold on the compromised system. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the target of the adversary in the Diamond Model.

B: The victim node represents the targeted person, organization, system, or asset. It directly fits this scenario because the requirement is to identify the target of the adversary in the Diamond Model.

C: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the target of the adversary in the Diamond Model.

D: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the target of the adversary in the Diamond Model.

E: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the target of the adversary in the Diamond Model.

Learning point: Use Diamond Model victim when the key requirement is to identify the target of the adversary in the Diamond Model.

Question 38

While supporting a manufacturing plant, an incident responder is asked to identify attacker-controlled domains or servers in the Diamond Model. Which concept or tool is the clearest match? The team wants the most defensible analyst action before expanding the investigation.

  1. Diamond Model infrastructure
  2. Kill-chain actions on objectives
  3. Diamond Model capability
  4. OWASP Testing Guide
  5. MITRE ATT&CK

Correct answer: A

Why: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. It directly fits this scenario because the requirement is to identify attacker-controlled domains or servers in the Diamond Model.

Option review:

A: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. It directly fits this scenario because the requirement is to identify attacker-controlled domains or servers in the Diamond Model.

B: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify attacker-controlled domains or servers in the Diamond Model.

C: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify attacker-controlled domains or servers in the Diamond Model.

D: The OWASP Testing Guide provides methodology and test ideas focused on web application security. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify attacker-controlled domains or servers in the Diamond Model.

E: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify attacker-controlled domains or servers in the Diamond Model.

Learning point: Use Diamond Model infrastructure when the key requirement is to identify attacker-controlled domains or servers in the Diamond Model.

Question 39

At Fourth Coffee, a security administrator has two simultaneous requirements: identify the malware or exploit used in the Diamond Model, and map the stage where a delivered exploit successfully abuses a vulnerability. Which TWO options should be selected? Select based on the scenario’s decisive constraint, not on which technology is newest.

  1. Kill-chain weaponization
  2. Diamond Model capability
  3. Kill-chain exploitation
  4. Kill-chain reconnaissance
  5. Diamond Model infrastructure

Correct answers: B, C

Why: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. It directly fits this scenario because the requirement is to identify the malware or exploit used in the Diamond Model. Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. It directly fits this scenario because the requirement is to map the stage where a delivered exploit successfully abuses a vulnerability.

Option review:

A: Weaponization prepares exploit code and payloads for use against a target. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the malware or exploit used in the Diamond Model; map the stage where a delivered exploit successfully abuses a vulnerability.

B: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. It directly fits this scenario because the requirement is to identify the malware or exploit used in the Diamond Model.

C: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. It directly fits this scenario because the requirement is to map the stage where a delivered exploit successfully abuses a vulnerability.

D: Reconnaissance gathers target information before attempting access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the malware or exploit used in the Diamond Model; map the stage where a delivered exploit successfully abuses a vulnerability.

E: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the malware or exploit used in the Diamond Model; map the stage where a delivered exploit successfully abuses a vulnerability.

Learning point: Use Diamond Model capability, Kill-chain exploitation when the key requirement is to identify the malware or exploit used in the Diamond Model; map the stage where a delivered exploit successfully abuses a vulnerability.

Question 40

The primary objective for Consolidated Messenger is to map observed behavior to standardized adversary techniques. Which selection best satisfies that objective in a customer-facing messaging service? Assume the activity is authorized and must follow normal enterprise change control.

  1. OWASP Testing Guide
  2. Diamond Model infrastructure
  3. Diamond Model adversary
  4. MITRE ATT&CK
  5. OSSTMM

Correct answer: D

Why: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. It directly fits this scenario because the requirement is to map observed behavior to standardized adversary techniques.

Option review:

A: The OWASP Testing Guide provides methodology and test ideas focused on web application security. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map observed behavior to standardized adversary techniques.

B: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map observed behavior to standardized adversary techniques.

C: The adversary node represents the actor responsible for the intrusion activity. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map observed behavior to standardized adversary techniques.

D: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. It directly fits this scenario because the requirement is to map observed behavior to standardized adversary techniques.

E: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map observed behavior to standardized adversary techniques.

Learning point: Use MITRE ATT&CK when the key requirement is to map observed behavior to standardized adversary techniques.

Popular posts

img