Posts

Showing posts with the label CS0-003

The Diamond Model Explained: Intrusion Analysis for the CySA+ Exam

The Diamond Model analyses a single intrusion event through four connected features. Its value is that establishing any one of them gives you a route to discovering the others — which is what makes it an investigative tool rather than a taxonomy. The four vertices Adversary — who is conducting the intrusion. The operator actually at the keyboard, and behind them the customer who benefits. Capability — what they use. Malware, exploits, stolen credentials, techniques. Infrastructure — what they use it from and through. Command and control servers, domains, IP addresses, email accounts, compromised third-party hosts. Victim — who is targeted. The organisation, and also the specific assets and people. The core axiom is worth stating as the model does: for every intrusion, an adversary uses a capability over some infrastructure against a victim. Every event has all four, even when you only know one. Pivoting — why the model is useful The diamond shape is not decoration. The vert...

Mean Time to Respond Explained: The MTTR Family for CySA+

Mean time to respond measures the average time between detecting an incident and taking effective action against it. It sits in the middle of the incident timeline, and its value is that it isolates one specific delay: how long an alert waits before somebody does something about it. The MTTR ambiguity Deal with this first, because it causes more confusion than the metric itself. MTTR is used for at least four different things: Mean time to respond — detection to action taken. Mean time to repair — start of repair work to service restored. Mean time to recover — failure to full service restoration. Mean time to remediate — vulnerability discovery to patch applied. On an exam, read the stem to see which is meant. In an organisation, define it in writing. Two teams reporting "MTTR" against different definitions will produce numbers that cannot be compared, and someone will eventually make a decision on the mismatch. The incident timeline Each metric measures a diff...

CVSS Explained: Base Metrics and Severity Scoring for CySA+

CVSS — the Common Vulnerability Scoring System — produces a 0 to 10 score expressing the technical severity of a vulnerability. CySA+ expects you to read a score, understand what drives it, and know its limits. The severity ranges Score Rating 0.0 None 0.1 – 3.9 Low 4.0 – 6.9 Medium 7.0 – 8.9 High 9.0 – 10.0 Critical Learn these boundaries. Questions frequently give a score and ask for the rating, or give a remediation SLA tied to ratings. The base metrics The base score is what vendors publish. It reflects intrinsic characteristics that do not change over time or between environments, and it is built from eight metrics in two groups. Exploitability metrics — how hard is it to exploit? Attack Vector — Network, Adjacent, Local or Physical. Network is the most severe, because it means remotely exploitable across the internet. Physical is the least, because it requires touching the device. Attack Complexity — Low or High. Low means no special conditions; High means the a...

The Cyber Kill Chain Explained: Attack Frameworks for CySA+

Attack frameworks give defenders a shared structure for describing how an intrusion unfolds. The Cyber Kill Chain is the oldest and most widely referenced, and its central idea is that an attacker must complete every stage while a defender only has to break one. The seven stages 1. Reconnaissance. Researching the target — OSINT, harvesting email addresses, mapping the external attack surface. Largely invisible to the defender, because most of it happens against third-party sources. 2. Weaponisation. Building the deliverable — pairing an exploit with a payload, crafting a malicious document. Happens entirely on the attacker's infrastructure, so there is nothing to detect. 3. Delivery. Getting it to the target: phishing email, malicious link, compromised website, USB device, exploiting an exposed service. This is the first stage the defender can observe and block , which is why email and web filtering carry so much weight. 4. Exploitation. Triggering the vulnerability — in s...