CompTIA CySA+ CS0-003 Attack Methodology Frameworks Practice Test
Objective 3.1 • 40 original questions
This CompTIA CySA+ CS0-003 practice test focuses on objective 3.1: attack methodology frameworks. All questions are original ExamSnap scenarios aligned to the official CS0-003 objective set; they are not copied from live CompTIA exam content. Review every option explanation to understand why a choice fits or does not fit the scenario. For broader exam preparation, review the CompTIA CySA+ CS0-003 Exam Dumps page.
Instructions: Select the best answer unless the question explicitly says Select TWO or Select THREE. Review the explanation and option review after answering.
Adventure Works is designing a combined control. It must map an attacker activity focused on researching people, systems, domains, or technologies, and identify the attacker entity in the Diamond Model. Which TWO options are most appropriate? Assume no additional product-specific features are available beyond the concepts listed.
Correct answers: D, E
Why: Reconnaissance gathers target information before attempting access. It directly fits this scenario because the requirement is to map an attacker activity focused on researching people, systems, domains, or technologies. The adversary node represents the actor responsible for the intrusion activity. It directly fits this scenario because the requirement is to identify the attacker entity in the Diamond Model.
Option review:
A: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map an attacker activity focused on researching people, systems, domains, or technologies; identify the attacker entity in the Diamond Model.
B: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map an attacker activity focused on researching people, systems, domains, or technologies; identify the attacker entity in the Diamond Model.
C: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map an attacker activity focused on researching people, systems, domains, or technologies; identify the attacker entity in the Diamond Model.
D: Reconnaissance gathers target information before attempting access. It directly fits this scenario because the requirement is to map an attacker activity focused on researching people, systems, domains, or technologies.
E: The adversary node represents the actor responsible for the intrusion activity. It directly fits this scenario because the requirement is to identify the attacker entity in the Diamond Model.
Learning point: Use Kill-chain reconnaissance, Diamond Model adversary when the key requirement is to map an attacker activity focused on researching people, systems, domains, or technologies; identify the attacker entity in the Diamond Model.
During an investigation at Wide World Importers, the immediate requirement is to map the stage where an attacker combines an exploit with a malicious payload. What should an incident coordinator select? The organization wants a vendor-neutral approach that can be explained during audit review.
Correct answer: B
Why: Weaponization prepares exploit code and payloads for use against a target. It directly fits this scenario because the requirement is to map the stage where an attacker combines an exploit with a malicious payload.
Option review:
A: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where an attacker combines an exploit with a malicious payload.
B: Weaponization prepares exploit code and payloads for use against a target. It directly fits this scenario because the requirement is to map the stage where an attacker combines an exploit with a malicious payload.
C: Reconnaissance gathers target information before attempting access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where an attacker combines an exploit with a malicious payload.
D: The adversary node represents the actor responsible for the intrusion activity. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where an attacker combines an exploit with a malicious payload.
E: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where an attacker combines an exploit with a malicious payload.
Learning point: Use Kill-chain weaponization when the key requirement is to map the stage where an attacker combines an exploit with a malicious payload.
Datum Fabrication is updating its security operations standard for a mixed Windows and Linux estate. Which option most directly helps the team map the stage where a malicious attachment or link is sent to the victim? Base the decision on the primary security requirement, not on implementation convenience.
Correct answer: D
Why: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. It directly fits this scenario because the requirement is to map the stage where a malicious attachment or link is sent to the victim.
Option review:
A: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a malicious attachment or link is sent to the victim.
B: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a malicious attachment or link is sent to the victim.
C: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a malicious attachment or link is sent to the victim.
D: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. It directly fits this scenario because the requirement is to map the stage where a malicious attachment or link is sent to the victim.
E: The adversary node represents the actor responsible for the intrusion activity. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a malicious attachment or link is sent to the victim.
Learning point: Use Kill-chain delivery when the key requirement is to map the stage where a malicious attachment or link is sent to the victim.
For an e-commerce platform, the team must accomplish both of these goals: map the stage where a delivered exploit successfully abuses a vulnerability, and identify the malware or exploit used in the Diamond Model. Which TWO choices together provide the best match? The environment follows least privilege and preserves evidence where incident handling is involved.
Correct answers: A, E
Why: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. It directly fits this scenario because the requirement is to map the stage where a delivered exploit successfully abuses a vulnerability. Capability represents malware, exploits, tools, techniques, or skills used by the adversary. It directly fits this scenario because the requirement is to identify the malware or exploit used in the Diamond Model.
Option review:
A: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. It directly fits this scenario because the requirement is to map the stage where a delivered exploit successfully abuses a vulnerability.
B: The OWASP Testing Guide provides methodology and test ideas focused on web application security. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a delivered exploit successfully abuses a vulnerability; identify the malware or exploit used in the Diamond Model.
C: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a delivered exploit successfully abuses a vulnerability; identify the malware or exploit used in the Diamond Model.
D: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a delivered exploit successfully abuses a vulnerability; identify the malware or exploit used in the Diamond Model.
E: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. It directly fits this scenario because the requirement is to identify the malware or exploit used in the Diamond Model.
Learning point: Use Kill-chain exploitation, Diamond Model capability when the key requirement is to map the stage where a delivered exploit successfully abuses a vulnerability; identify the malware or exploit used in the Diamond Model.
In a restricted research segment, a malware analyst must map the stage where malicious code is installed for continued access. Which approach is MOST appropriate? Use the choice that most directly addresses the stated evidence rather than a broader control.
Correct answer: B
Why: Installation establishes malware or another persistent foothold on the compromised system. It directly fits this scenario because the requirement is to map the stage where malicious code is installed for continued access.
Option review:
A: The victim node represents the targeted person, organization, system, or asset. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malicious code is installed for continued access.
B: Installation establishes malware or another persistent foothold on the compromised system. It directly fits this scenario because the requirement is to map the stage where malicious code is installed for continued access.
C: Reconnaissance gathers target information before attempting access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malicious code is installed for continued access.
D: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malicious code is installed for continued access.
E: The OWASP Testing Guide provides methodology and test ideas focused on web application security. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malicious code is installed for continued access.
Learning point: Use Kill-chain installation when the key requirement is to map the stage where malicious code is installed for continued access.
During a security review, a SOC analyst must address two separate needs: map the stage where malware begins receiving remote instructions, and select a broad methodology for structured operational security testing. Select TWO. The team wants the most defensible analyst action before expanding the investigation.
Correct answers: A, C
Why: Command and control creates a communication channel through which the attacker can direct compromised systems. It directly fits this scenario because the requirement is to map the stage where malware begins receiving remote instructions. The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. It directly fits this scenario because the requirement is to select a broad methodology for structured operational security testing.
Option review:
A: Command and control creates a communication channel through which the attacker can direct compromised systems. It directly fits this scenario because the requirement is to map the stage where malware begins receiving remote instructions.
B: Installation establishes malware or another persistent foothold on the compromised system. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malware begins receiving remote instructions; select a broad methodology for structured operational security testing.
C: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. It directly fits this scenario because the requirement is to select a broad methodology for structured operational security testing.
D: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malware begins receiving remote instructions; select a broad methodology for structured operational security testing.
E: The adversary node represents the actor responsible for the intrusion activity. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malware begins receiving remote instructions; select a broad methodology for structured operational security testing.
Learning point: Use Kill-chain command and control, OSSTMM when the key requirement is to map the stage where malware begins receiving remote instructions; select a broad methodology for structured operational security testing.
a threat hunter at Woodgrove Bank is comparing several approaches. The deciding requirement is to map the stage where the adversary exfiltrates data or disrupts business operations. Which option should be chosen? Select based on the scenario’s decisive constraint, not on which technology is newest.
Correct answer: A
Why: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. It directly fits this scenario because the requirement is to map the stage where the adversary exfiltrates data or disrupts business operations.
Option review:
A: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. It directly fits this scenario because the requirement is to map the stage where the adversary exfiltrates data or disrupts business operations.
B: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where the adversary exfiltrates data or disrupts business operations.
C: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where the adversary exfiltrates data or disrupts business operations.
D: Command and control creates a communication channel through which the attacker can direct compromised systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where the adversary exfiltrates data or disrupts business operations.
E: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where the adversary exfiltrates data or disrupts business operations.
Learning point: Use Kill-chain actions on objectives when the key requirement is to map the stage where the adversary exfiltrates data or disrupts business operations.
While supporting a regulated customer-data environment, a risk analyst is asked to identify the attacker entity in the Diamond Model. Which concept or tool is the clearest match? Assume the activity is authorized and must follow normal enterprise change control.
Correct answer: A
Why: The adversary node represents the actor responsible for the intrusion activity. It directly fits this scenario because the requirement is to identify the attacker entity in the Diamond Model.
Option review:
A: The adversary node represents the actor responsible for the intrusion activity. It directly fits this scenario because the requirement is to identify the attacker entity in the Diamond Model.
B: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the attacker entity in the Diamond Model.
C: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the attacker entity in the Diamond Model.
D: The victim node represents the targeted person, organization, system, or asset. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the attacker entity in the Diamond Model.
E: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the attacker entity in the Diamond Model.
Learning point: Use Diamond Model adversary when the key requirement is to identify the attacker entity in the Diamond Model.
A new security procedure at Contoso Health must enable analysts to identify the target of the adversary in the Diamond Model. Which option is the BEST choice? Assume no additional product-specific features are available beyond the concepts listed.
Correct answer: A
Why: The victim node represents the targeted person, organization, system, or asset. It directly fits this scenario because the requirement is to identify the target of the adversary in the Diamond Model.
Option review:
A: The victim node represents the targeted person, organization, system, or asset. It directly fits this scenario because the requirement is to identify the target of the adversary in the Diamond Model.
B: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the target of the adversary in the Diamond Model.
C: The adversary node represents the actor responsible for the intrusion activity. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the target of the adversary in the Diamond Model.
D: Installation establishes malware or another persistent foothold on the compromised system. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the target of the adversary in the Diamond Model.
E: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the target of the adversary in the Diamond Model.
Learning point: Use Diamond Model victim when the key requirement is to identify the target of the adversary in the Diamond Model.
The primary objective for Blue Yonder Airlines is to identify attacker-controlled domains or servers in the Diamond Model. Which selection best satisfies that objective in an airline operations network? The organization wants a vendor-neutral approach that can be explained during audit review.
Correct answer: B
Why: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. It directly fits this scenario because the requirement is to identify attacker-controlled domains or servers in the Diamond Model.
Option review:
A: Installation establishes malware or another persistent foothold on the compromised system. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify attacker-controlled domains or servers in the Diamond Model.
B: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. It directly fits this scenario because the requirement is to identify attacker-controlled domains or servers in the Diamond Model.
C: Weaponization prepares exploit code and payloads for use against a target. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify attacker-controlled domains or servers in the Diamond Model.
D: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify attacker-controlled domains or servers in the Diamond Model.
E: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify attacker-controlled domains or servers in the Diamond Model.
Learning point: Use Diamond Model infrastructure when the key requirement is to identify attacker-controlled domains or servers in the Diamond Model.
At Lucerne Publishing, a detection engineer needs to identify the malware or exploit used in the Diamond Model. Which option is the BEST fit for a remote-work environment? Base the decision on the primary security requirement, not on implementation convenience.
Correct answer: E
Why: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. It directly fits this scenario because the requirement is to identify the malware or exploit used in the Diamond Model.
Option review:
A: Weaponization prepares exploit code and payloads for use against a target. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the malware or exploit used in the Diamond Model.
B: Command and control creates a communication channel through which the attacker can direct compromised systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the malware or exploit used in the Diamond Model.
C: Installation establishes malware or another persistent foothold on the compromised system. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the malware or exploit used in the Diamond Model.
D: The victim node represents the targeted person, organization, system, or asset. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the malware or exploit used in the Diamond Model.
E: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. It directly fits this scenario because the requirement is to identify the malware or exploit used in the Diamond Model.
Learning point: Use Diamond Model capability when the key requirement is to identify the malware or exploit used in the Diamond Model.
During an investigation at Fabrikam Finance, the immediate requirement is to map observed behavior to standardized adversary techniques. What should a vulnerability analyst select? The environment follows least privilege and preserves evidence where incident handling is involved.
Correct answer: D
Why: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. It directly fits this scenario because the requirement is to map observed behavior to standardized adversary techniques.
Option review:
A: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map observed behavior to standardized adversary techniques.
B: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map observed behavior to standardized adversary techniques.
C: Reconnaissance gathers target information before attempting access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map observed behavior to standardized adversary techniques.
D: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. It directly fits this scenario because the requirement is to map observed behavior to standardized adversary techniques.
E: Weaponization prepares exploit code and payloads for use against a target. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map observed behavior to standardized adversary techniques.
Learning point: Use MITRE ATT&CK when the key requirement is to map observed behavior to standardized adversary techniques.
City Power Utilities is updating its security operations standard for a segmented industrial environment. Which option most directly helps the team select a broad methodology for structured operational security testing? Use the choice that most directly addresses the stated evidence rather than a broader control.
Correct answer: D
Why: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. It directly fits this scenario because the requirement is to select a broad methodology for structured operational security testing.
Option review:
A: The victim node represents the targeted person, organization, system, or asset. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a broad methodology for structured operational security testing.
B: The adversary node represents the actor responsible for the intrusion activity. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a broad methodology for structured operational security testing.
C: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a broad methodology for structured operational security testing.
D: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. It directly fits this scenario because the requirement is to select a broad methodology for structured operational security testing.
E: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a broad methodology for structured operational security testing.
Learning point: Use OSSTMM when the key requirement is to select a broad methodology for structured operational security testing.
During a security review, a security consultant must address two separate needs: select a testing methodology specifically focused on web applications, and map the stage where the adversary exfiltrates data or disrupts business operations. Select TWO. The team wants the most defensible analyst action before expanding the investigation.
Correct answers: B, C
Why: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. It directly fits this scenario because the requirement is to map the stage where the adversary exfiltrates data or disrupts business operations. The OWASP Testing Guide provides methodology and test ideas focused on web application security. It directly fits this scenario because the requirement is to select a testing methodology specifically focused on web applications.
Option review:
A: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a testing methodology specifically focused on web applications; map the stage where the adversary exfiltrates data or disrupts business operations.
B: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. It directly fits this scenario because the requirement is to map the stage where the adversary exfiltrates data or disrupts business operations.
C: The OWASP Testing Guide provides methodology and test ideas focused on web application security. It directly fits this scenario because the requirement is to select a testing methodology specifically focused on web applications.
D: Weaponization prepares exploit code and payloads for use against a target. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a testing methodology specifically focused on web applications; map the stage where the adversary exfiltrates data or disrupts business operations.
E: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a testing methodology specifically focused on web applications; map the stage where the adversary exfiltrates data or disrupts business operations.
Learning point: Use OWASP Testing Guide, Kill-chain actions on objectives when the key requirement is to select a testing methodology specifically focused on web applications; map the stage where the adversary exfiltrates data or disrupts business operations.
At Northwind Traders, a security engineer has two simultaneous requirements: map an attacker activity focused on researching people, systems, domains, or technologies, and identify the attacker entity in the Diamond Model. Which TWO options should be selected? Select based on the scenario’s decisive constraint, not on which technology is newest.
Correct answers: A, B
Why: Reconnaissance gathers target information before attempting access. It directly fits this scenario because the requirement is to map an attacker activity focused on researching people, systems, domains, or technologies. The adversary node represents the actor responsible for the intrusion activity. It directly fits this scenario because the requirement is to identify the attacker entity in the Diamond Model.
Option review:
A: Reconnaissance gathers target information before attempting access. It directly fits this scenario because the requirement is to map an attacker activity focused on researching people, systems, domains, or technologies.
B: The adversary node represents the actor responsible for the intrusion activity. It directly fits this scenario because the requirement is to identify the attacker entity in the Diamond Model.
C: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map an attacker activity focused on researching people, systems, domains, or technologies; identify the attacker entity in the Diamond Model.
D: Weaponization prepares exploit code and payloads for use against a target. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map an attacker activity focused on researching people, systems, domains, or technologies; identify the attacker entity in the Diamond Model.
E: Command and control creates a communication channel through which the attacker can direct compromised systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map an attacker activity focused on researching people, systems, domains, or technologies; identify the attacker entity in the Diamond Model.
Learning point: Use Kill-chain reconnaissance, Diamond Model adversary when the key requirement is to map an attacker activity focused on researching people, systems, domains, or technologies; identify the attacker entity in the Diamond Model.
A review at Alpine Ski House finds a gap: the team cannot reliably map the stage where an attacker combines an exploit with a malicious payload. Which option best closes that gap? Assume the activity is authorized and must follow normal enterprise change control.
Correct answer: B
Why: Weaponization prepares exploit code and payloads for use against a target. It directly fits this scenario because the requirement is to map the stage where an attacker combines an exploit with a malicious payload.
Option review:
A: Command and control creates a communication channel through which the attacker can direct compromised systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where an attacker combines an exploit with a malicious payload.
B: Weaponization prepares exploit code and payloads for use against a target. It directly fits this scenario because the requirement is to map the stage where an attacker combines an exploit with a malicious payload.
C: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where an attacker combines an exploit with a malicious payload.
D: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where an attacker combines an exploit with a malicious payload.
E: The victim node represents the targeted person, organization, system, or asset. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where an attacker combines an exploit with a malicious payload.
Learning point: Use Kill-chain weaponization when the key requirement is to map the stage where an attacker combines an exploit with a malicious payload.
a systems security analyst at Coho Winery is comparing several approaches. The deciding requirement is to map the stage where a malicious attachment or link is sent to the victim. Which option should be chosen? Assume no additional product-specific features are available beyond the concepts listed.
Correct answer: A
Why: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. It directly fits this scenario because the requirement is to map the stage where a malicious attachment or link is sent to the victim.
Option review:
A: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. It directly fits this scenario because the requirement is to map the stage where a malicious attachment or link is sent to the victim.
B: The victim node represents the targeted person, organization, system, or asset. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a malicious attachment or link is sent to the victim.
C: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a malicious attachment or link is sent to the victim.
D: Installation establishes malware or another persistent foothold on the compromised system. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a malicious attachment or link is sent to the victim.
E: Command and control creates a communication channel through which the attacker can direct compromised systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a malicious attachment or link is sent to the victim.
Learning point: Use Kill-chain delivery when the key requirement is to map the stage where a malicious attachment or link is sent to the victim.
During a security review, an incident responder must address two separate needs: map the stage where a delivered exploit successfully abuses a vulnerability, and identify the malware or exploit used in the Diamond Model. Select TWO. The organization wants a vendor-neutral approach that can be explained during audit review.
Correct answers: A, E
Why: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. It directly fits this scenario because the requirement is to map the stage where a delivered exploit successfully abuses a vulnerability. Capability represents malware, exploits, tools, techniques, or skills used by the adversary. It directly fits this scenario because the requirement is to identify the malware or exploit used in the Diamond Model.
Option review:
A: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. It directly fits this scenario because the requirement is to map the stage where a delivered exploit successfully abuses a vulnerability.
B: Command and control creates a communication channel through which the attacker can direct compromised systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a delivered exploit successfully abuses a vulnerability; identify the malware or exploit used in the Diamond Model.
C: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a delivered exploit successfully abuses a vulnerability; identify the malware or exploit used in the Diamond Model.
D: The OWASP Testing Guide provides methodology and test ideas focused on web application security. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a delivered exploit successfully abuses a vulnerability; identify the malware or exploit used in the Diamond Model.
E: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. It directly fits this scenario because the requirement is to identify the malware or exploit used in the Diamond Model.
Learning point: Use Kill-chain exploitation, Diamond Model capability when the key requirement is to map the stage where a delivered exploit successfully abuses a vulnerability; identify the malware or exploit used in the Diamond Model.
At Fourth Coffee, a security administrator has two simultaneous requirements: map the stage where malicious code is installed for continued access, and map observed behavior to standardized adversary techniques. Which TWO options should be selected? Base the decision on the primary security requirement, not on implementation convenience.
Correct answers: C, E
Why: Installation establishes malware or another persistent foothold on the compromised system. It directly fits this scenario because the requirement is to map the stage where malicious code is installed for continued access. MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. It directly fits this scenario because the requirement is to map observed behavior to standardized adversary techniques.
Option review:
A: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malicious code is installed for continued access; map observed behavior to standardized adversary techniques.
B: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malicious code is installed for continued access; map observed behavior to standardized adversary techniques.
C: Installation establishes malware or another persistent foothold on the compromised system. It directly fits this scenario because the requirement is to map the stage where malicious code is installed for continued access.
D: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malicious code is installed for continued access; map observed behavior to standardized adversary techniques.
E: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. It directly fits this scenario because the requirement is to map observed behavior to standardized adversary techniques.
Learning point: Use Kill-chain installation, MITRE ATT&CK when the key requirement is to map the stage where malicious code is installed for continued access; map observed behavior to standardized adversary techniques.
For a customer-facing messaging service, the team must accomplish both of these goals: map the stage where malware begins receiving remote instructions, and select a broad methodology for structured operational security testing. Which TWO choices together provide the best match? The environment follows least privilege and preserves evidence where incident handling is involved.
Correct answers: B, D
Why: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. It directly fits this scenario because the requirement is to select a broad methodology for structured operational security testing. Command and control creates a communication channel through which the attacker can direct compromised systems. It directly fits this scenario because the requirement is to map the stage where malware begins receiving remote instructions.
Option review:
A: The OWASP Testing Guide provides methodology and test ideas focused on web application security. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malware begins receiving remote instructions; select a broad methodology for structured operational security testing.
B: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. It directly fits this scenario because the requirement is to select a broad methodology for structured operational security testing.
C: The victim node represents the targeted person, organization, system, or asset. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malware begins receiving remote instructions; select a broad methodology for structured operational security testing.
D: Command and control creates a communication channel through which the attacker can direct compromised systems. It directly fits this scenario because the requirement is to map the stage where malware begins receiving remote instructions.
E: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malware begins receiving remote instructions; select a broad methodology for structured operational security testing.
Learning point: Use Kill-chain command and control, OSSTMM when the key requirement is to map the stage where malware begins receiving remote instructions; select a broad methodology for structured operational security testing.
At Adventure Works, a blue-team analyst needs to map the stage where the adversary exfiltrates data or disrupts business operations. Which option is the BEST fit for a hybrid-cloud workload? Use the choice that most directly addresses the stated evidence rather than a broader control.
Correct answer: D
Why: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. It directly fits this scenario because the requirement is to map the stage where the adversary exfiltrates data or disrupts business operations.
Option review:
A: Installation establishes malware or another persistent foothold on the compromised system. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where the adversary exfiltrates data or disrupts business operations.
B: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where the adversary exfiltrates data or disrupts business operations.
C: Reconnaissance gathers target information before attempting access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where the adversary exfiltrates data or disrupts business operations.
D: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. It directly fits this scenario because the requirement is to map the stage where the adversary exfiltrates data or disrupts business operations.
E: The adversary node represents the actor responsible for the intrusion activity. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where the adversary exfiltrates data or disrupts business operations.
Learning point: Use Kill-chain actions on objectives when the key requirement is to map the stage where the adversary exfiltrates data or disrupts business operations.
During an investigation at Wide World Importers, the immediate requirement is to identify the attacker entity in the Diamond Model. What should an incident coordinator select? The team wants the most defensible analyst action before expanding the investigation.
Correct answer: C
Why: The adversary node represents the actor responsible for the intrusion activity. It directly fits this scenario because the requirement is to identify the attacker entity in the Diamond Model.
Option review:
A: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the attacker entity in the Diamond Model.
B: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the attacker entity in the Diamond Model.
C: The adversary node represents the actor responsible for the intrusion activity. It directly fits this scenario because the requirement is to identify the attacker entity in the Diamond Model.
D: The OWASP Testing Guide provides methodology and test ideas focused on web application security. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the attacker entity in the Diamond Model.
E: Reconnaissance gathers target information before attempting access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the attacker entity in the Diamond Model.
Learning point: Use Diamond Model adversary when the key requirement is to identify the attacker entity in the Diamond Model.
Datum Fabrication is updating its security operations standard for a mixed Windows and Linux estate. Which option most directly helps the team identify the target of the adversary in the Diamond Model? Select based on the scenario’s decisive constraint, not on which technology is newest.
Correct answer: B
Why: The victim node represents the targeted person, organization, system, or asset. It directly fits this scenario because the requirement is to identify the target of the adversary in the Diamond Model.
Option review:
A: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the target of the adversary in the Diamond Model.
B: The victim node represents the targeted person, organization, system, or asset. It directly fits this scenario because the requirement is to identify the target of the adversary in the Diamond Model.
C: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the target of the adversary in the Diamond Model.
D: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the target of the adversary in the Diamond Model.
E: The adversary node represents the actor responsible for the intrusion activity. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the target of the adversary in the Diamond Model.
Learning point: Use Diamond Model victim when the key requirement is to identify the target of the adversary in the Diamond Model.
A ticket at Tailspin Toys asks a SOC lead to identify attacker-controlled domains or servers in the Diamond Model. Which choice addresses the requirement most directly? Assume the activity is authorized and must follow normal enterprise change control.
Correct answer: B
Why: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. It directly fits this scenario because the requirement is to identify attacker-controlled domains or servers in the Diamond Model.
Option review:
A: Installation establishes malware or another persistent foothold on the compromised system. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify attacker-controlled domains or servers in the Diamond Model.
B: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. It directly fits this scenario because the requirement is to identify attacker-controlled domains or servers in the Diamond Model.
C: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify attacker-controlled domains or servers in the Diamond Model.
D: The victim node represents the targeted person, organization, system, or asset. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify attacker-controlled domains or servers in the Diamond Model.
E: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify attacker-controlled domains or servers in the Diamond Model.
Learning point: Use Diamond Model infrastructure when the key requirement is to identify attacker-controlled domains or servers in the Diamond Model.
At Proseware Research, the response plan has three distinct requirements: identify the malware or exploit used in the Diamond Model; map an attacker activity focused on researching people, systems, domains, or technologies; and map the stage where malicious code is installed for continued access. Which THREE options should be selected? Assume no additional product-specific features are available beyond the concepts listed.
Correct answers: B, C, E
Why: Reconnaissance gathers target information before attempting access. It directly fits this scenario because the requirement is to map an attacker activity focused on researching people, systems, domains, or technologies. Installation establishes malware or another persistent foothold on the compromised system. It directly fits this scenario because the requirement is to map the stage where malicious code is installed for continued access. Capability represents malware, exploits, tools, techniques, or skills used by the adversary. It directly fits this scenario because the requirement is to identify the malware or exploit used in the Diamond Model.
Option review:
A: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the malware or exploit used in the Diamond Model; map an attacker activity focused on researching people, systems, domains, or technologies; map the stage where malicious code is installed for continued access.
B: Reconnaissance gathers target information before attempting access. It directly fits this scenario because the requirement is to map an attacker activity focused on researching people, systems, domains, or technologies.
C: Installation establishes malware or another persistent foothold on the compromised system. It directly fits this scenario because the requirement is to map the stage where malicious code is installed for continued access.
D: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the malware or exploit used in the Diamond Model; map an attacker activity focused on researching people, systems, domains, or technologies; map the stage where malicious code is installed for continued access.
E: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. It directly fits this scenario because the requirement is to identify the malware or exploit used in the Diamond Model.
Learning point: Use Diamond Model capability, Kill-chain reconnaissance, Kill-chain installation when the key requirement is to identify the malware or exploit used in the Diamond Model; map an attacker activity focused on researching people, systems, domains, or technologies; map the stage where malicious code is installed for continued access.
A review at Wingtip Services finds a gap: the team cannot reliably map observed behavior to standardized adversary techniques. Which option best closes that gap? The organization wants a vendor-neutral approach that can be explained during audit review.
Correct answer: C
Why: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. It directly fits this scenario because the requirement is to map observed behavior to standardized adversary techniques.
Option review:
A: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map observed behavior to standardized adversary techniques.
B: Command and control creates a communication channel through which the attacker can direct compromised systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map observed behavior to standardized adversary techniques.
C: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. It directly fits this scenario because the requirement is to map observed behavior to standardized adversary techniques.
D: The adversary node represents the actor responsible for the intrusion activity. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map observed behavior to standardized adversary techniques.
E: Installation establishes malware or another persistent foothold on the compromised system. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map observed behavior to standardized adversary techniques.
Learning point: Use MITRE ATT&CK when the key requirement is to map observed behavior to standardized adversary techniques.
a threat hunter at Woodgrove Bank is comparing several approaches. The deciding requirement is to select a broad methodology for structured operational security testing. Which option should be chosen? Base the decision on the primary security requirement, not on implementation convenience.
Correct answer: C
Why: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. It directly fits this scenario because the requirement is to select a broad methodology for structured operational security testing.
Option review:
A: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a broad methodology for structured operational security testing.
B: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a broad methodology for structured operational security testing.
C: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. It directly fits this scenario because the requirement is to select a broad methodology for structured operational security testing.
D: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a broad methodology for structured operational security testing.
E: The victim node represents the targeted person, organization, system, or asset. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a broad methodology for structured operational security testing.
Learning point: Use OSSTMM when the key requirement is to select a broad methodology for structured operational security testing.
While supporting a regulated customer-data environment, a risk analyst is asked to select a testing methodology specifically focused on web applications. Which concept or tool is the clearest match? The environment follows least privilege and preserves evidence where incident handling is involved.
Correct answer: A
Why: The OWASP Testing Guide provides methodology and test ideas focused on web application security. It directly fits this scenario because the requirement is to select a testing methodology specifically focused on web applications.
Option review:
A: The OWASP Testing Guide provides methodology and test ideas focused on web application security. It directly fits this scenario because the requirement is to select a testing methodology specifically focused on web applications.
B: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a testing methodology specifically focused on web applications.
C: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a testing methodology specifically focused on web applications.
D: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a testing methodology specifically focused on web applications.
E: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to select a testing methodology specifically focused on web applications.
Learning point: Use OWASP Testing Guide when the key requirement is to select a testing methodology specifically focused on web applications.
An audit follow-up for a customer-facing service records that the investigation has already ruled out routine administrative activity. To close the finding, the team must map an attacker activity focused on researching people, systems, domains, or technologies; and identify the attacker entity in the Diamond Model. Which option should the analyst recommend?
Correct answers: B, E
Why: The adversary node represents the actor responsible for the intrusion activity. It directly fits this scenario because the requirement is to identify the attacker entity in the Diamond Model. Reconnaissance gathers target information before attempting access. It directly fits this scenario because the requirement is to map an attacker activity focused on researching people, systems, domains, or technologies.
Option review:
A: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map an attacker activity focused on researching people, systems, domains, or technologies; identify the attacker entity in the Diamond Model.
B: The adversary node represents the actor responsible for the intrusion activity. It directly fits this scenario because the requirement is to identify the attacker entity in the Diamond Model.
C: Command and control creates a communication channel through which the attacker can direct compromised systems. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map an attacker activity focused on researching people, systems, domains, or technologies; identify the attacker entity in the Diamond Model.
D: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map an attacker activity focused on researching people, systems, domains, or technologies; identify the attacker entity in the Diamond Model.
E: Reconnaissance gathers target information before attempting access. It directly fits this scenario because the requirement is to map an attacker activity focused on researching people, systems, domains, or technologies.
Learning point: Use Kill-chain reconnaissance, Diamond Model adversary when the key requirement is to map an attacker activity focused on researching people, systems, domains, or technologies; identify the attacker entity in the Diamond Model.
The primary objective for Blue Yonder Airlines is to map the stage where an attacker combines an exploit with a malicious payload. Which selection best satisfies that objective in an airline operations network? The team wants the most defensible analyst action before expanding the investigation.
Correct answer: D
Why: Weaponization prepares exploit code and payloads for use against a target. It directly fits this scenario because the requirement is to map the stage where an attacker combines an exploit with a malicious payload.
Option review:
A: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where an attacker combines an exploit with a malicious payload.
B: Installation establishes malware or another persistent foothold on the compromised system. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where an attacker combines an exploit with a malicious payload.
C: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where an attacker combines an exploit with a malicious payload.
D: Weaponization prepares exploit code and payloads for use against a target. It directly fits this scenario because the requirement is to map the stage where an attacker combines an exploit with a malicious payload.
E: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where an attacker combines an exploit with a malicious payload.
Learning point: Use Kill-chain weaponization when the key requirement is to map the stage where an attacker combines an exploit with a malicious payload.
At Lucerne Publishing, a detection engineer needs to map the stage where a malicious attachment or link is sent to the victim. Which option is the BEST fit for a remote-work environment? Select based on the scenario’s decisive constraint, not on which technology is newest.
Correct answer: D
Why: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. It directly fits this scenario because the requirement is to map the stage where a malicious attachment or link is sent to the victim.
Option review:
A: The adversary node represents the actor responsible for the intrusion activity. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a malicious attachment or link is sent to the victim.
B: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a malicious attachment or link is sent to the victim.
C: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a malicious attachment or link is sent to the victim.
D: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. It directly fits this scenario because the requirement is to map the stage where a malicious attachment or link is sent to the victim.
E: The victim node represents the targeted person, organization, system, or asset. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a malicious attachment or link is sent to the victim.
Learning point: Use Kill-chain delivery when the key requirement is to map the stage where a malicious attachment or link is sent to the victim.
In a research enclave, the evidence has been normalized and timestamps are trustworthy. The team has already ruled out unrelated controls and now must map the stage where a delivered exploit successfully abuses a vulnerability; and identify the malware or exploit used in the Diamond Model. Which choice is most defensible?
Correct answers: B, E
Why: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. It directly fits this scenario because the requirement is to identify the malware or exploit used in the Diamond Model. Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. It directly fits this scenario because the requirement is to map the stage where a delivered exploit successfully abuses a vulnerability.
Option review:
A: Reconnaissance gathers target information before attempting access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a delivered exploit successfully abuses a vulnerability; identify the malware or exploit used in the Diamond Model.
B: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. It directly fits this scenario because the requirement is to identify the malware or exploit used in the Diamond Model.
C: The adversary node represents the actor responsible for the intrusion activity. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a delivered exploit successfully abuses a vulnerability; identify the malware or exploit used in the Diamond Model.
D: The victim node represents the targeted person, organization, system, or asset. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where a delivered exploit successfully abuses a vulnerability; identify the malware or exploit used in the Diamond Model.
E: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. It directly fits this scenario because the requirement is to map the stage where a delivered exploit successfully abuses a vulnerability.
Learning point: Use Kill-chain exploitation, Diamond Model capability when the key requirement is to map the stage where a delivered exploit successfully abuses a vulnerability; identify the malware or exploit used in the Diamond Model.
City Power Utilities is designing a combined control. It must map the stage where malicious code is installed for continued access, and map observed behavior to standardized adversary techniques. Which TWO options are most appropriate? Assume no additional product-specific features are available beyond the concepts listed.
Correct answers: A, E
Why: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. It directly fits this scenario because the requirement is to map observed behavior to standardized adversary techniques. Installation establishes malware or another persistent foothold on the compromised system. It directly fits this scenario because the requirement is to map the stage where malicious code is installed for continued access.
Option review:
A: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. It directly fits this scenario because the requirement is to map observed behavior to standardized adversary techniques.
B: Reconnaissance gathers target information before attempting access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malicious code is installed for continued access; map observed behavior to standardized adversary techniques.
C: The adversary node represents the actor responsible for the intrusion activity. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malicious code is installed for continued access; map observed behavior to standardized adversary techniques.
D: The victim node represents the targeted person, organization, system, or asset. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malicious code is installed for continued access; map observed behavior to standardized adversary techniques.
E: Installation establishes malware or another persistent foothold on the compromised system. It directly fits this scenario because the requirement is to map the stage where malicious code is installed for continued access.
Learning point: Use Kill-chain installation, MITRE ATT&CK when the key requirement is to map the stage where malicious code is installed for continued access; map observed behavior to standardized adversary techniques.
A ticket at A. Datum Logistics asks a security consultant to map the stage where malware begins receiving remote instructions. Which choice addresses the requirement most directly? The organization wants a vendor-neutral approach that can be explained during audit review.
Correct answer: C
Why: Command and control creates a communication channel through which the attacker can direct compromised systems. It directly fits this scenario because the requirement is to map the stage where malware begins receiving remote instructions.
Option review:
A: Installation establishes malware or another persistent foothold on the compromised system. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malware begins receiving remote instructions.
B: The OWASP Testing Guide provides methodology and test ideas focused on web application security. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malware begins receiving remote instructions.
C: Command and control creates a communication channel through which the attacker can direct compromised systems. It directly fits this scenario because the requirement is to map the stage where malware begins receiving remote instructions.
D: Weaponization prepares exploit code and payloads for use against a target. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malware begins receiving remote instructions.
E: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where malware begins receiving remote instructions.
Learning point: Use Kill-chain command and control when the key requirement is to map the stage where malware begins receiving remote instructions.
In a regional distribution network, a security engineer must map the stage where the adversary exfiltrates data or disrupts business operations. Which approach is MOST appropriate? Base the decision on the primary security requirement, not on implementation convenience.
Correct answer: C
Why: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. It directly fits this scenario because the requirement is to map the stage where the adversary exfiltrates data or disrupts business operations.
Option review:
A: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where the adversary exfiltrates data or disrupts business operations.
B: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where the adversary exfiltrates data or disrupts business operations.
C: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. It directly fits this scenario because the requirement is to map the stage where the adversary exfiltrates data or disrupts business operations.
D: Installation establishes malware or another persistent foothold on the compromised system. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where the adversary exfiltrates data or disrupts business operations.
E: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map the stage where the adversary exfiltrates data or disrupts business operations.
Learning point: Use Kill-chain actions on objectives when the key requirement is to map the stage where the adversary exfiltrates data or disrupts business operations.
For a SaaS-heavy business, a cloud security analyst must satisfy all three needs: identify the attacker entity in the Diamond Model; map observed behavior to standardized adversary techniques; and map the stage where an attacker combines an exploit with a malicious payload. Select THREE. The environment follows least privilege and preserves evidence where incident handling is involved.
Correct answers: A, D, E
Why: The adversary node represents the actor responsible for the intrusion activity. It directly fits this scenario because the requirement is to identify the attacker entity in the Diamond Model. MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. It directly fits this scenario because the requirement is to map observed behavior to standardized adversary techniques. Weaponization prepares exploit code and payloads for use against a target. It directly fits this scenario because the requirement is to map the stage where an attacker combines an exploit with a malicious payload.
Option review:
A: The adversary node represents the actor responsible for the intrusion activity. It directly fits this scenario because the requirement is to identify the attacker entity in the Diamond Model.
B: Delivery transmits the weaponized payload to the target through email, web, removable media, or another channel. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the attacker entity in the Diamond Model; map observed behavior to standardized adversary techniques; map the stage where an attacker combines an exploit with a malicious payload.
C: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the attacker entity in the Diamond Model; map observed behavior to standardized adversary techniques; map the stage where an attacker combines an exploit with a malicious payload.
D: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. It directly fits this scenario because the requirement is to map observed behavior to standardized adversary techniques.
E: Weaponization prepares exploit code and payloads for use against a target. It directly fits this scenario because the requirement is to map the stage where an attacker combines an exploit with a malicious payload.
Learning point: Use Diamond Model adversary, MITRE ATT&CK, Kill-chain weaponization when the key requirement is to identify the attacker entity in the Diamond Model; map observed behavior to standardized adversary techniques; map the stage where an attacker combines an exploit with a malicious payload.
a systems security analyst at Coho Winery is comparing several approaches. The deciding requirement is to identify the target of the adversary in the Diamond Model. Which option should be chosen? Use the choice that most directly addresses the stated evidence rather than a broader control.
Correct answer: B
Why: The victim node represents the targeted person, organization, system, or asset. It directly fits this scenario because the requirement is to identify the target of the adversary in the Diamond Model.
Option review:
A: Installation establishes malware or another persistent foothold on the compromised system. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the target of the adversary in the Diamond Model.
B: The victim node represents the targeted person, organization, system, or asset. It directly fits this scenario because the requirement is to identify the target of the adversary in the Diamond Model.
C: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the target of the adversary in the Diamond Model.
D: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the target of the adversary in the Diamond Model.
E: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the target of the adversary in the Diamond Model.
Learning point: Use Diamond Model victim when the key requirement is to identify the target of the adversary in the Diamond Model.
While supporting a manufacturing plant, an incident responder is asked to identify attacker-controlled domains or servers in the Diamond Model. Which concept or tool is the clearest match? The team wants the most defensible analyst action before expanding the investigation.
Correct answer: A
Why: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. It directly fits this scenario because the requirement is to identify attacker-controlled domains or servers in the Diamond Model.
Option review:
A: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. It directly fits this scenario because the requirement is to identify attacker-controlled domains or servers in the Diamond Model.
B: Actions on objectives are the attacker activities that accomplish the ultimate goal, such as theft, disruption, or destruction. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify attacker-controlled domains or servers in the Diamond Model.
C: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify attacker-controlled domains or servers in the Diamond Model.
D: The OWASP Testing Guide provides methodology and test ideas focused on web application security. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify attacker-controlled domains or servers in the Diamond Model.
E: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify attacker-controlled domains or servers in the Diamond Model.
Learning point: Use Diamond Model infrastructure when the key requirement is to identify attacker-controlled domains or servers in the Diamond Model.
At Fourth Coffee, a security administrator has two simultaneous requirements: identify the malware or exploit used in the Diamond Model, and map the stage where a delivered exploit successfully abuses a vulnerability. Which TWO options should be selected? Select based on the scenario’s decisive constraint, not on which technology is newest.
Correct answers: B, C
Why: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. It directly fits this scenario because the requirement is to identify the malware or exploit used in the Diamond Model. Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. It directly fits this scenario because the requirement is to map the stage where a delivered exploit successfully abuses a vulnerability.
Option review:
A: Weaponization prepares exploit code and payloads for use against a target. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the malware or exploit used in the Diamond Model; map the stage where a delivered exploit successfully abuses a vulnerability.
B: Capability represents malware, exploits, tools, techniques, or skills used by the adversary. It directly fits this scenario because the requirement is to identify the malware or exploit used in the Diamond Model.
C: Exploitation triggers a vulnerability or weakness to execute attacker-controlled behavior. It directly fits this scenario because the requirement is to map the stage where a delivered exploit successfully abuses a vulnerability.
D: Reconnaissance gathers target information before attempting access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the malware or exploit used in the Diamond Model; map the stage where a delivered exploit successfully abuses a vulnerability.
E: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to identify the malware or exploit used in the Diamond Model; map the stage where a delivered exploit successfully abuses a vulnerability.
Learning point: Use Diamond Model capability, Kill-chain exploitation when the key requirement is to identify the malware or exploit used in the Diamond Model; map the stage where a delivered exploit successfully abuses a vulnerability.
The primary objective for Consolidated Messenger is to map observed behavior to standardized adversary techniques. Which selection best satisfies that objective in a customer-facing messaging service? Assume the activity is authorized and must follow normal enterprise change control.
Correct answer: D
Why: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. It directly fits this scenario because the requirement is to map observed behavior to standardized adversary techniques.
Option review:
A: The OWASP Testing Guide provides methodology and test ideas focused on web application security. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map observed behavior to standardized adversary techniques.
B: Infrastructure represents domains, IP addresses, servers, accounts, or services used to conduct the operation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map observed behavior to standardized adversary techniques.
C: The adversary node represents the actor responsible for the intrusion activity. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map observed behavior to standardized adversary techniques.
D: MITRE ATT&CK catalogs adversary tactics and techniques based on observed behavior and is useful for detection mapping and threat hunting. It directly fits this scenario because the requirement is to map observed behavior to standardized adversary techniques.
E: The Open Source Security Testing Methodology Manual provides a structured methodology for security testing and operational security measurement. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to map observed behavior to standardized adversary techniques.
Learning point: Use MITRE ATT&CK when the key requirement is to map observed behavior to standardized adversary techniques.
Popular posts
Recent Posts
