Objective 2.1
Cybersecurity Defense AnalystRecognize common types of attacks and attack vectors
Objective 2.1 sits in Threat and Attack Types, Motivations, and Tactics, which carries 20% of the Cybersecurity Defense Analyst exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.
Objective title verbatim from the official objectives. Splunk exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
An analyst is asked how MITRE classifies all forms of phishing, whatever the delivery channel. What does the documentation say?
Correct.
Checked against attack.mitre.org, August 2026Concept
Phishing works on a person rather than on a control. That is why filtering alone never closes it, and why the same technique survives every change of protocol.
Why A
MITRE documents that all forms of phishing are electronically delivered social engineering, whether targeted or sent in mass campaigns.
Source
MITRE ATT&CK: Phishing, T1566, checked August 2026Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering.
Now you: objective 2.1 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
An analyst reads that phishing aimed at one named company is given a specific name. Which term does MITRE use?
Sample question 2 of 3
An analyst asks what makes internal spearphishing different from ordinary phishing. What does MITRE document?
Sample question 3 of 3
An analyst investigates traffic that appears normal but carries adversary commands. Which MITRE technique describes hiding commands inside ordinary protocol traffic?
Full Cybersecurity Defense Analyst question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.
More objectives in Threat and Attack Types, Motivations, and Tactics
- 2.2 Define common terms including supply chain attack, ransomware, registry, exfiltration, social engineering, DoS, DDoS, bot and botnet, C2, zero trust, account takeover, email compromise, threat actor, APT, adversary
- 2.3 Identify the common tiers of Threat Intelligence and how they might be applied to threat analysis
- 2.4 Outline the purpose and scope of annotations within Splunk Enterprise Security
- 2.5 Define tactics, techniques and procedures and how they are regarded in the industry