QuestionQ22

Incident Response and Management

A security architect examines a report from a third-party incident-response consultant and notes the following:

Question Image

Which of the following frameworks did the consultant use to conduct the analysis?

  • A Spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege (STRIDE)
  • B MITRE ATT&CK
  • C Diamond Model of Intrusion Analysis
  • D National Institute of Standards and Technology (NIST) Cybersecurity Framework
  • E Cyber Kill Chain
Explanation

The Diamond Model of Intrusion Analysis represents an intrusion through four core elements: adversary, infrastructure, capability, and victim. The reported attacker, custom command-and-control and PowerShell infrastructure, custom backdoor capability, and financial-institution victims map directly to those elements.

Community Discussion

No comments yet. Be the first to start the discussion!