200-201 Question 400
Select 4An organization has detected a potential intrusion in their network. During the investigation, the security team identifies the use of a specific malware sample, the communication channel it used to connect to a command and control server, and the adversary's apparent intent to exfiltrate sensitive data. Using the Diamond Model of Intrusion, which core features should the team document to fully map the intrusion?
- A
Adversary
- B
Victim
- C
Infrastructure
- D
Capabilities
- E
Incident Response Timeline
- F
Mitigation Plan
Show answer and explanation
Correct answers: A, B, C, D
Explanation
The Diamond Model of Intrusion maps four core features: Adversary, Victim, Infrastructure, and Capabilities. These elements help analysts understand the relationships and behaviors involved in an intrusion, allowing for a structured approach to analysis and response. Features like 'Incident Response Timeline' and 'Mitigation Plan' are important for handling incidents but are not part of the Diamond Model framework.
- A. Correct.
Adversary is one of the core features of the Diamond Model, representing the threat actor behind the intrusion.
- B. Correct.
Victim is another core feature of the Diamond Model, which identifies the target of the intrusion.
- C. Correct.
Infrastructure refers to the system, servers, or tools used by the adversary to conduct the attack, making it a core feature in the model.
- D. Correct.
Capabilities refer to the tools, techniques, and procedures (TTPs) employed by the adversary, also a core feature of the Diamond Model.
- E. Incorrect.
Incident Response Timeline is not a part of the Diamond Model but rather a practical tool for incident handling and recovery.
- F. Incorrect.
Mitigation Plan is a response strategy and not a component of the Diamond Model.