Objective 2.5
Cybersecurity Defense AnalystDefine tactics, techniques and procedures and how they are regarded in the industry
Objective 2.5 sits in Threat and Attack Types, Motivations, and Tactics, which carries 20% of the Cybersecurity Defense Analyst exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.
Objective title verbatim from the official objectives. Splunk exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
An analyst asks what a tactic represents in ATT&CK. Which answer matches the documentation?
Correct.
Checked against attack.mitre.org, August 2026Concept
Separating why from how is what makes the matrix usable for coverage. A team can ask whether it can see any technique serving a goal, rather than chasing tool names.
Why A
MITRE documents that tactics represent the why of an ATT&CK technique: the adversary's tactical goal and the reason for performing an action.
Source
MITRE ATT&CK: Frequently Asked Questions, checked August 2026It is the adversary's tactical goal: the reason for performing an action. For example, an adversary may want to achieve credential access.
Now you: objective 2.5 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
An analyst asks what an ATT&CK technique represents. Which answer matches the documentation?
Sample question 2 of 3
An analyst asks what a procedure is in ATT&CK terms. Which answer matches the documentation?
Sample question 3 of 3
An analyst compares ATT&CK with the Cyber Kill Chain. Which difference does MITRE document?
Full Cybersecurity Defense Analyst question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.
More objectives in Threat and Attack Types, Motivations, and Tactics
- 2.1 Recognize common types of attacks and attack vectors
- 2.2 Define common terms including supply chain attack, ransomware, registry, exfiltration, social engineering, DoS, DDoS, bot and botnet, C2, zero trust, account takeover, email compromise, threat actor, APT, adversary
- 2.3 Identify the common tiers of Threat Intelligence and how they might be applied to threat analysis
- 2.4 Outline the purpose and scope of annotations within Splunk Enterprise Security