Quiz 10 Question 1 of 20

An analyst reviews an incident where a phishing email delivered an attachment, then PowerShell ran on the endpoint. The CISO wants a model that clearly separates the email delivery phase from the endpoint execution phase, with pre-compromise versus post-compromise activity. Which framework should the analyst use?

Select an answer to reveal the explanation.

Motivation