nerdexam
Cisco

100-160 · Question #31

Drag and Drop Question You need to diagram an intrusion event by using the Diamond Model. Move each event detail from the list on the left to the correct location in the diagram on the right. Note…

The correct answer is Ransomware Group; Working Email; Malware; Email Server, Domain Name; Customer and Product Documents; Product Dossiers. Diamond Model of Intrusion Analysis - Explained What is the Diamond Model? The Diamond Model is a framework for analyzing cyber intrusions. It has four core vertices: `` Adversary / \ / \ Capability Infrastructure \ / \ / Victim `` This question uses an expanded 6-slot version…

Cybersecurity Incident Response

Question

Drag and Drop Question You need to diagram an intrusion event by using the Diamond Model. Move each event detail from the list on the left to the correct location in the diagram on the right. Note: You will receive partial credit for each correct response. Answer:

Exhibit

100-160 question #31 exhibit

Answer Area

Drag items

Product DossiersRansomware GroupWorking EmailMalwareEmail Server, Domain NameCustomer and Product Documents

Correct arrangement

  • Ransomware Group
  • Working Email
  • Malware
  • Email Server, Domain Name
  • Customer and Product Documents
  • Product Dossiers

Explanation

Diamond Model of Intrusion Analysis - Explained

What is the Diamond Model?

The Diamond Model is a framework for analyzing cyber intrusions. It has four core vertices:

         Adversary
        /          \
       /            \
Capability      Infrastructure
       \            /
        \          /
          Victim

This question uses an expanded 6-slot version that breaks down each vertex into more granular detail. Here's the full mapping:


Item-by-Item Breakdown

1. Ransomware Group → Adversary

The threat actor driving the attack. The adversary is who is responsible - in this case, an organized ransomware group. This is always the starting point of any Diamond Model analysis.

Common mistake: Confusing the adversary with their tools. The group is the adversary; the malware is their capability.


2. Working Email → Adversary's Operational Resource / Delivery Vector

The working email is the adversary's operational account used to send phishing lures. It sits closer to the adversary vertex because it represents the persona/identity layer the attacker uses to interact with the victim - not just infrastructure, but the specific mechanism of social engineering contact.

Common mistake: Placing this under Victim. The email belongs to the attacker, not the target.


3. Malware → Capability

Capability = the weapon. Malware (ransomware payload) is the tool the adversary deploys to achieve their objective. This is the how they attack, not how they deliver or who they target.

Common mistake: Confusing capability with infrastructure. Malware is the weapon; the email server is the delivery channel.


4. Email Server, Domain Name → Infrastructure

Infrastructure = the physical/logical resources the adversary controls to deliver their capability. The email server and spoofed/controlled domain are the technical backbone used to route the phishing attack.

Common mistake: Grouping "Working Email" and "Email Server" together. The account (working email) is the adversary's operational identity; the server and domain are the technical infrastructure hosting it.


5. Customer and Product Documents → Victim (Assets)

This represents what the victim organization possesses - the data residing on their systems. The victim vertex identifies both the target organization and what they hold that makes them valuable to the adversary.

Common mistake: Placing stolen data here and under adversary. The documents belong to the victim until compromised.


6. Product Dossiers → Victim (Targeted Intelligence / Impact)

Product Dossiers represent the specific intelligence or sensitive data the ransomware group was after - the ultimate objective of the intrusion. This expands the victim vertex to show what was exfiltrated or held for ransom, distinguishing the victim's general assets (#5) from the specific high-value target (#6).

Common mistake: This is the trickiest item. Students often place it under Adversary (as recon data the attacker gathered). However, in the Diamond Model context, it belongs on the Victim side because it represents victim-owned sensitive material that motivated or resulted from the attack.


Key Takeaway

PositionDiamond VertexItem
1AdversaryRansomware Group
2Adversary's Vector/PersonaWorking Email
3CapabilityMalware
4InfrastructureEmail Server, Domain Name
5Victim (General Assets)Customer and Product Documents
6Victim (Targeted/Stolen Data)Product Dossiers

The model traces the attack from who attackedhow they connectedwhat weapon they usedwhat infrastructure they usedwho they hitwhat they took.

Topics

#Diamond Model#intrusion analysis#threat modeling#adversary attribution

Community Discussion

No community discussion yet for this question.

Full 100-160 Practice