CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium
A security analyst is investigating a brute-force attack attempt against an internal SSH server. The firewall logs show numerous failed login attempts originating from a single internal IP address (192.168.1.100) over a short period. This IP address belongs to a developer's workstation. Which phase of the Diamond Model of Intrusion Analysis would focus on identifying the specific tools or techniques used by the attacker from this workstation to perform the brute-force attempts?
- AAdversary
- BVictim
- CCapability
- DInfrastructure
Show answer & explanationAnswer & explanation
Correct answer: C. Capability
The 'Capability' facet of the Diamond Model focuses on the tools, techniques, and methodologies used by the adversary. In this scenario, identifying the specific tools or techniques for the brute-force attempts (e.g., Hydra, Nmap scripts, custom scripts) falls directly under Capability.
Why the other options are wrong
- A. Adversary focuses on the attacker's identity, motivation, and intent.
- B. Victim focuses on the target of the attack (e.g., the SSH server, the organization).
- D. Infrastructure focuses on the physical or logical communication paths and systems used by the adversary (e.g., C2 servers, attack origin IPs). While the workstation is infrastructure, the *tools/techniques* used from it are capability.
Diamond Model: Capability
One of the four core facets of the Diamond Model of Intrusion Analysis, representing the adversary's tools, techniques, and methodologies used to execute an intrusion.
- Includes exploits, malware, custom scripts, and specific attack procedures.
- Answers the question: 'How did the adversary perform the attack?'
- Focuses on the means of the attack.
Memory trick: Adversary, Capability, Infrastructure, Victim – The 'ACIV' of every attack!