200-201 · Question #356
A user received a suspicious email and reported it to the SOC team. After analysis, the team concluded that it was a spear phishing attack. According to the Diamond Model, how is the phishing email ca
The correct answer is C. adversary. According to the Diamond Model of Intrusion Analysis, a spear phishing email, serving as the delivery mechanism and a method used by the attacker, is categorized under the "Adversary" component.
Question
A user received a suspicious email and reported it to the SOC team. After analysis, the team concluded that it was a spear phishing attack. According to the Diamond Model, how is the phishing email categorized?
Options
- Acapability
- Binfrastructure
- Cadversary
- Dvictim
How the community answered
(54 responses)- A6% (3)
- B2% (1)
- C89% (48)
- D4% (2)
Why each option
According to the Diamond Model of Intrusion Analysis, a spear phishing email, serving as the delivery mechanism and a method used by the attacker, is categorized under the "Adversary" component.
''Capability'' refers to the tools, techniques, and procedures (TTPs) the adversary uses, but the *email itself* is more directly tied to the adversary's action of delivering the attack.
''Infrastructure'' refers to the physical and logical resources the adversary uses to conduct the attack (e.g., C2 servers, domain names), not the phishing email content or delivery itself.
According to the Diamond Model, the "Adversary" component describes the attacker, their characteristics, and their capabilities, including the methods or techniques they use for an attack, such as crafting and sending a spear phishing email.
''Victim'' refers to the target of the attack, including characteristics about the victim, not the attack method itself.
Concept tested: Diamond Model of Intrusion Analysis components
Topics
Community Discussion
No community discussion yet for this question.