During a phishing incident, a SOC analyst has a malware sample, an attacker C2 server, a compromised employee account, and an infected workstation. Using the Diamond Model, which mapping is correct?
Select an answer to reveal the explanation.
Short Explanation
Think of the Diamond Model as four seats at a crime scene table: who did it, what they used, where they worked, and who got hit. If you map the malware to the tool seat and the C2 to the plumbing seat, the rest falls into place. The account is the adversary identity, not the victim, because the adversary is using it.
Full Explanation
The Diamond Model separates an event into adversary, capability, infrastructure, and victim so analysts can reason about relationships instead of naming a single tool. A malware sample is a capability because it is the technique or tool used to affect the target. A command-and-control server is infrastructure because it is the location, service, or resource used by the adversary to communicate or operate. A compromised employee account represents the adversary element when it is the identity being abused to act inside the environment, while the infected workstation is the victim because it is the asset or person being affected. A mapping that calls malware infrastructure confuses the tool with the location; C2 is not the method but the channel. A mapping that calls the account victim mistakes the abused identity for the harmed asset; the account is the foothold, not the endpoint being damaged. A mapping that calls the workstation capability reverses roles because the workstation is being acted upon, not the instrument of attack. Exam caveat: Diamond Model questions often hinge on whether an artifact is the actor, the method, the location, or the target. Operational check: For each artifact, ask who or what is acting, what is being used, where communication occurs, and what is harmed, then place it on the diamond.