Objective 2.1

Cybersecurity Defense Analyst

Recognize common types of attacks and attack vectors

Objective 2.1 sits in Threat and Attack Types, Motivations, and Tactics, which carries 20% of the Cybersecurity Defense Analyst exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.

Objective title verbatim from the official objectives. Splunk exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

2-1Threat and Attack Types, Motivations, and Tactics

An analyst is asked how MITRE classifies all forms of phishing, whatever the delivery channel. What does the documentation say?

Delivered social engineeringCorrect · your answerCorrect.
Automated credential stuffingCredential stuffing replays stolen passwords rather than tricking a person.
A form of privilege escalationEscalation happens after access rather than in the delivery.
A network layer attackPhishing operates at the application and human layer instead.

Correct.

Checked against attack.mitre.org, August 2026

Concept

Phishing works on a person rather than on a control. That is why filtering alone never closes it, and why the same technique survives every change of protocol.

Why A

MITRE documents that all forms of phishing are electronically delivered social engineering, whether targeted or sent in mass campaigns.

Source

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering.

MITRE ATT&CK: Phishing, T1566, checked August 2026
#phishing#attack types

Now you: objective 2.1 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

2-1Threat and Attack Types, Motivations, and Tactics

An analyst reads that phishing aimed at one named company is given a specific name. Which term does MITRE use?

Sample question 2 of 3

2-1Threat and Attack Types, Motivations, and Tactics

An analyst asks what makes internal spearphishing different from ordinary phishing. What does MITRE document?

Sample question 3 of 3

2-1Threat and Attack Types, Motivations, and Tactics

An analyst investigates traffic that appears normal but carries adversary commands. Which MITRE technique describes hiding commands inside ordinary protocol traffic?

Full Cybersecurity Defense Analyst question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Threat and Attack Types, Motivations, and Tactics