Objective 2.2

Cybersecurity Defense Analyst

Define common terms including supply chain attack, ransomware, registry, exfiltration, social engineering, DoS, DDoS, bot and botnet, C2, zero trust, account takeover, email compromise, threat actor, APT, adversary

Objective 2.2 sits in Threat and Attack Types, Motivations, and Tactics, which carries 20% of the Cybersecurity Defense Analyst exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.

Objective title verbatim from the official objectives. Splunk exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

2-2Threat and Attack Types, Motivations, and Tactics

An analyst is asked to define exfiltration for a report. Which description matches the ATT&CK tactic?

Deleting audit recordsRemoving audit records falls under defence evasion.
Encrypting data in placeEncrypting data in place is the Impact tactic instead.
Escalating account privilegesPrivilege escalation is a separate tactical goal.
Stealing data from the networkCorrect · your answerCorrect.

Correct.

Checked against attack.mitre.org, August 2026

Concept

Naming the goal separately from the method is what lets one detection cover many channels. The data leaves whether it goes by web upload, DNS or a courier.

Why D

MITRE documents Exfiltration as the tactic where the adversary is trying to steal data, using techniques to remove it from the network.

Source

Exfiltration consists of techniques that adversaries may use to steal data from your network. Once they've collected data, adversaries often package it to avoid detection while removing it.

MITRE ATT&CK: Exfiltration, TA0010, checked August 2026
#exfiltration#terminology

Now you: objective 2.2 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

2-2Threat and Attack Types, Motivations, and Tactics

An analyst is writing a definition of ransomware for an incident report. Which description matches the MITRE technique?

Sample question 2 of 3

2-2Threat and Attack Types, Motivations, and Tactics

An analyst needs a definition of a supply chain attack for a risk report. Which matches the NIST glossary?

Sample question 3 of 3

2-2Threat and Attack Types, Motivations, and Tactics

An analyst asks for the NIST definition of denial of service. Which description matches?

Full Cybersecurity Defense Analyst question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Threat and Attack Types, Motivations, and Tactics