macOS · Intermediate

MITRE ATT&CK SOC Analyst Quiz

Section 3: macOS — Intermediate (Questions 1–20)

Every other question asks you to type in the correct MITRE ATT&CK tactic and technique yourself — use the ATT&CK Navigator to find them. The remaining questions give you multiple-choice options, but watch out for decoys mixed in.

How to Answer Each Question

For each scenario, answer 5 components:

  1. Attacker Objective — What is the attacker trying to achieve?
  2. MITRE ATT&CK Tactic — Which tactic(s)? (On alternating questions you’ll type your answer instead of choosing from options.)
  3. Technique / Sub-technique — Which technique(s) apply? (Same: alternating between multiple-choice and free-text.)
  4. Key Evidence — What specific evidence supports your mapping?
  5. Next Likely Step — What will the attacker do next?

Scoring

ComponentPoints
Attacker Objective1 point
Correct Tactic2 points
Correct Technique + ID3 points
Evidence Analysis2 points
Next Likely Step2 points

Maximum: 200 points (10 per question × 20 questions)