SPLK-5001 · Question #74
What is the following step-by-step description an example of? 1. The attacker devises a non-default beacon profile with Cobalt Strike and embeds this within a document. 2. The attacker creates a…
The correct answer is D. Technique. Technique is correct because this scenario describes a specific, named attack method - spearphishing with a custom Cobalt Strike C2 profile - executed through a defined sequence of steps. In the TTP (Tactics, Techniques, and Procedures) model, a technique is the how: a concrete…
Question
Options
- ATactic
- BPolicy
- CProcedure
- DTechnique
How the community answered
(40 responses)- A10% (4)
- B5% (2)
- C3% (1)
- D83% (33)
Explanation
Technique is correct because this scenario describes a specific, named attack method - spearphishing with a custom Cobalt Strike C2 profile - executed through a defined sequence of steps. In the TTP (Tactics, Techniques, and Procedures) model, a technique is the how: a concrete attack method that can be documented, reproduced, and mapped (e.g., to MITRE ATT&CK).
Tactic (A) is wrong because a tactic is the high-level goal, such as "Initial Access" or "Command and Control" - not the specific method used to achieve it. Policy (B) is wrong because policies are organizational rules or governance documents, not attack descriptions. Procedure (C) is the most tempting distractor, but in this model a procedure refers to an organization's internal security process, not an attacker's methodology.
Memory tip: Think of the acronym TTP as a zoom lens - Tactic is wide-angle (the goal), Technique is mid-zoom (the method), and Procedure is close-up (the org's response process). A step-by-step attack description = mid-zoom = Technique.
Topics
Community Discussion
No community discussion yet for this question.