100-160 · Question #31
Drag and Drop Question You need to diagram an intrusion event by using the Diamond Model. Move each event detail from the list on the left to the correct location in the diagram on the right. Note…
The correct answer is Ransomware Group; Working Email; Malware; Email Server, Domain Name; Customer and Product Documents; Product Dossiers. Diamond Model of Intrusion Analysis - Explained What is the Diamond Model? The Diamond Model is a framework for analyzing cyber intrusions. It has four core vertices: `` Adversary / \ / \ Capability Infrastructure \ / \ / Victim `` This question uses an expanded 6-slot version…
Question
Drag and Drop Question You need to diagram an intrusion event by using the Diamond Model. Move each event detail from the list on the left to the correct location in the diagram on the right. Note: You will receive partial credit for each correct response. Answer:
Exhibit
Answer Area
Drag items
Correct arrangement
- Ransomware Group
- Working Email
- Malware
- Email Server, Domain Name
- Customer and Product Documents
- Product Dossiers
Explanation
Diamond Model of Intrusion Analysis - Explained
What is the Diamond Model?
The Diamond Model is a framework for analyzing cyber intrusions. It has four core vertices:
Adversary
/ \
/ \
Capability Infrastructure
\ /
\ /
Victim
This question uses an expanded 6-slot version that breaks down each vertex into more granular detail. Here's the full mapping:
Item-by-Item Breakdown
1. Ransomware Group → Adversary
The threat actor driving the attack. The adversary is who is responsible - in this case, an organized ransomware group. This is always the starting point of any Diamond Model analysis.
Common mistake: Confusing the adversary with their tools. The group is the adversary; the malware is their capability.
2. Working Email → Adversary's Operational Resource / Delivery Vector
The working email is the adversary's operational account used to send phishing lures. It sits closer to the adversary vertex because it represents the persona/identity layer the attacker uses to interact with the victim - not just infrastructure, but the specific mechanism of social engineering contact.
Common mistake: Placing this under Victim. The email belongs to the attacker, not the target.
3. Malware → Capability
Capability = the weapon. Malware (ransomware payload) is the tool the adversary deploys to achieve their objective. This is the how they attack, not how they deliver or who they target.
Common mistake: Confusing capability with infrastructure. Malware is the weapon; the email server is the delivery channel.
4. Email Server, Domain Name → Infrastructure
Infrastructure = the physical/logical resources the adversary controls to deliver their capability. The email server and spoofed/controlled domain are the technical backbone used to route the phishing attack.
Common mistake: Grouping "Working Email" and "Email Server" together. The account (working email) is the adversary's operational identity; the server and domain are the technical infrastructure hosting it.
5. Customer and Product Documents → Victim (Assets)
This represents what the victim organization possesses - the data residing on their systems. The victim vertex identifies both the target organization and what they hold that makes them valuable to the adversary.
Common mistake: Placing stolen data here and under adversary. The documents belong to the victim until compromised.
6. Product Dossiers → Victim (Targeted Intelligence / Impact)
Product Dossiers represent the specific intelligence or sensitive data the ransomware group was after - the ultimate objective of the intrusion. This expands the victim vertex to show what was exfiltrated or held for ransom, distinguishing the victim's general assets (#5) from the specific high-value target (#6).
Common mistake: This is the trickiest item. Students often place it under Adversary (as recon data the attacker gathered). However, in the Diamond Model context, it belongs on the Victim side because it represents victim-owned sensitive material that motivated or resulted from the attack.
Key Takeaway
| Position | Diamond Vertex | Item |
|---|---|---|
| 1 | Adversary | Ransomware Group |
| 2 | Adversary's Vector/Persona | Working Email |
| 3 | Capability | Malware |
| 4 | Infrastructure | Email Server, Domain Name |
| 5 | Victim (General Assets) | Customer and Product Documents |
| 6 | Victim (Targeted/Stolen Data) | Product Dossiers |
The model traces the attack from who attacked → how they connected → what weapon they used → what infrastructure they used → who they hit → what they took.
Topics
Community Discussion
No community discussion yet for this question.
