Threat and Attack Types, Motivations, and Tactics
SPLK-5001 · 60 questions
- City employees click a fake timesheet-correction message that harvests Microsoft 365 passwords. What is the attack vector?
- A parking-kiosk vendor plugs an unmanaged laptop into the city VLAN and wormable malware spreads. What introduced the attack?
- Overnight logs show thousands of failed logons against the city's SSL-VPN used by public-works staff. How should the analyst classify this activity?
- Residents cannot reach the tax-assessor site, and netflow shows a flood of SYN packets from many sources. What attack is occurring?
- After a successful phish, a court clerk's mailbox now forwards all mail to an external Gmail address. What continuing attack should the analyst name?
- An attacker uses a stolen help-desk token to reset the utilities-billing administrator. What attack type is this?
- A USB drive left in the library parking lot is plugged into a catalog PC. What is the attack vector?
- A public-facing permits API is abused with SQL-injection-style input. What is the attack vector?
- The water SCADA historian is reachable from the business VLAN because a jump host is dual-homed. What enabling vector should the analyst report?
- During finals week, students rent a botnet and flood the school-grade portal until it is unreachable. How should the analyst describe the attack?
- An insider at the assessor's office copies the property-tax database to a personal cloud drive. What attack type is this?
- A compromised municipal parks-events WordPress page drops a loader on a staff browser. What delivery vector is this?
- Attackers scan a forgotten facilities camera server and find RDP listening on the internet. What is the attack surface?
- A fake city-benefits enrollment site captures logins after staff approve a flood of MFA prompts. What access method is this?
- Malware on a clerk workstation talks to a rare external IP on a high port every 60 seconds. What stage is this pattern?
- A vendor update for the parking-meter backend includes a trojanized installer. What is the attack vector?
- County GIS clients auto-update from a compromised publisher after an email announced the patch. Which named term fits the compromise of that trusted update path?
- Library file servers show mass encryption and a payment note. Which term names this behavior?
- Persistence on a permitting workstation is created with a Windows Run key. In this blueprint, what does registry mean?
- Large night-time uploads leave the health-clinic file share for an unknown S3 bucket. Which term names that activity?
- A city help-desk clerk resets a privileged password after a caller claims to be the CIO and cites an urgent council meeting. Enterprise Security shows no exploit payload, no C2 session, and no stolen token. Which term correctly classifies this attack?
- One angry resident saturates the city's parks-reservation form from a single home IP until the page stops responding. Web logs show no botnet, no distinct source swarm, and no account theft. Which term correctly describes this event?
- The 911 public non-emergency web tip form is overwhelmed by concurrent POST traffic from thousands of distinct source IPs worldwide. Which term correctly describes this attack?
- A single licensing-counter kiosk at the city's DMV-style office is compromised and phones home. Days later, dozens of similar kiosks report to the same controller. How should the analyst label the one host versus the coordinated collection?
- After malware executes on a city clerk workstation, the host opens a periodic encrypted session to an attacker-controlled VPS and waits for instructions. Which term describes that ongoing remote channel?
- The city is adopting zero trust so a finance clerk on the "inside" VLAN is still challenged and granted only the access needed for the job. What does that design actually mean?
- An attacker already has the city treasurer's mailbox password and now enrolls a new MFA method and creates hidden mailbox rules. Which term best describes this stage?
- After a successful phish, a vendor-payment thread is sent from the city comptroller's real mailbox asking a contractor to change the ACH destination. Which term best describes this activity?
- During reconnaissance against the city's 911 CAD, analysts recover a commodity scanner sample. Who or what is the threat actor (adversary) in this incident?
- For months, a stealthy operator uses custom tools against the county elections office, staying quiet and adapting when a host is rebuilt. Which term correctly labels this campaign?
- After a noisy weekend ransomware hit on a library public PC, staff start calling every attacker an "APT." How should the civic SOC correct that mix-up?
- After social engineering produced account takeover of a finance clerk, the actor used the mailbox for email compromise. Splunk now shows large uploads of tax-roll files to an external host. Which blueprint term names the current stage?
- The county board asks whether nation-state actors are targeting U.S. local government this year so it can set budget and risk appetite. Which threat-intelligence tier answers that question?
- An ISAC bulletin describes a campaign expected against U.S. water utilities over the next quarter and lists likely TTPs. Which intelligence tier is that for the city's water SOC?
- Overnight, a feed arrives with IPs, domains, and hashes matching last night's parking-meter malware. What is the right use of that intelligence in Splunk Enterprise Security?
- One bulletin says a crew targeting city halls "uses scheduled tasks and signed binaries for persistence." Another gives a single SHA-256. How should the analyst classify those two pieces?
- The city's threat-intel program loads only file hashes into Enterprise Security. Actors targeting clerk PCs change hashes daily. What should the SOC do?
- An ISAC strategic report says municipal finance systems are a rising target this year. What is the best use of that report inside the city's Enterprise Security program?
- Operational intelligence says a ransomware affiliate is targeting municipal Microsoft 365 this week. What should the city SOC analyst do first?
- Technical intelligence provides a C2 domain used against other city networks. How should the civic SOC operationalize it?
- Using the Pyramid of Pain, how should a city SOC weight a file hash from technical intel versus a tactic from tactical intel?
- A public-health SOC receives strategic, operational, tactical, and technical intelligence in one packet. The night analyst's question is "what do I search for tonight?" Which tier primarily answers that?
- A transit detection engineer attaches MITRE ATT&CK technique IDs to a correlation search. What are those attachments, and why do they matter on Incident Review?
- A court SOC adds ATT&CK annotations to a correlation search that has not matched in months. Staff expect a notable because the annotation is present. What is the correct scope of annotations?
- A risk notable for a city finance user lists annotations from several contributing risk events, each mapping a different ATT&CK technique. What is the intended use of that stacked view?
- A court SOC wants CIS Controls and NIST mappings on the same notables that already show MITRE ATT&CK. What should the defense analyst understand about Enterprise Security annotations?
- After ransomware on a courthouse file server was missed, an analyst wants to stamp last week's notables with a new ATT&CK annotation so the gap looks covered. Why will that not fix the miss?
- A city attorney asks what a courthouse notable actually means. The analyst has the correlation-search SPL and an annotation whose tactic name is Credential Access. Which language should the analyst use in the briefing?
- On a municipal SOC, who usually creates Enterprise Security annotations on a correlation search or risk rule, and who consumes them during triage?
- A wastewater notable is noisy, but its annotation shows ATT&CK Execution. How should the hunter use that annotation next?
- A municipal SOC is documenting an LSASS dump on a finance workstation. How should the analyst label the three TTP layers?
- Two ransomware crews hitting city hall both phish, use valid accounts, then encrypt, but they use different lure text and encryptors. How should the industry regard those TTPs?
- A city SOC inventories only file hashes from a library incident and has no technique IDs. What must it add before it can describe the campaign in the industry's common TTP language?
- A county SOC rewrites detections every time a ransomware encryptor hash changes. What Pyramid of Pain lesson should guide more durable civic detections?
- A transit analyst treats Lockheed Martin Kill Chain "C2" and MITRE ATT&CK "Command and Control" as the same vocabulary. What distinction should the analyst keep?
- After a courthouse intrusion, a civic SOC wants to blog the exact command line its detection used. Why is publishing that procedure-level detail operationally risky?
- An elections hunter writes the hypothesis "the adversary will use T1053 Scheduled Task for persistence on poll-book images." What kind of TTP hypothesis is that?
- A public-health SOC uses Diamond Model capability alongside ATT&CK techniques on the same campaign. What should the analyst conclude?
- A sheriff's office analyst labels every PowerShell event a tactic. What is the correct TTP placement?
- Why does a municipal ISAC share "we saw T1078 Valid Accounts" instead of victim usernames?