212-82 · Question #147
A large-scale financial Institution was targeted by a sophisticated cyber-attack that resulted In substantial data leakage and financial loss. The attack was unique in its execution, involving…
The correct answer is A. MITRE ATT&CK, encompassing a wide range of tactics and techniques used in real-world attacks. To analyze a complex, multi-stage cyber-attack pattern and revise defense strategies, the MITRE ATT&CK framework is the most suitable as it catalogs adversary tactics and techniques observed in real-world attacks.
Question
A large-scale financial Institution was targeted by a sophisticated cyber-attack that resulted In substantial data leakage and financial loss. The attack was unique in its execution, involving multiple stages and techniques that evaded traditional security measures. The institution's cybersecurity team, in their post-incident analysis, discovered that the attackers followed a complex methodology aligning with a well-known hacking framework. Identifying the framework used by the attackers is crucial for the institution to revise its defense strategies. Which of the following hacking frameworks/methodologles most likely corresponds to the attack pattern observed?
Options
- AMITRE ATT&CK, encompassing a wide range of tactics and techniques used in real-world attacks
- BOWASP Top Ten. focusing on web application security risks
- CISO/IEC 27001. focusing on information security management systems
- DNIST Cybersecurity Framework, primarily used for managing cybersecurity risks
How the community answered
(26 responses)- A88% (23)
- C8% (2)
- D4% (1)
Why each option
To analyze a complex, multi-stage cyber-attack pattern and revise defense strategies, the MITRE ATT&CK framework is the most suitable as it catalogs adversary tactics and techniques observed in real-world attacks.
The MITRE ATT&CK framework is a comprehensive, globally accessible knowledge base of adversary tactics and techniques based on real-world observations, making it ideal for mapping complex, multi-stage attack patterns and understanding adversary methodologies for defense strategy revision.
The OWASP Top Ten focuses specifically on the most critical web application security risks and is not designed as a framework for analyzing sophisticated, multi-stage network attacks.
ISO/IEC 27001 is an international standard for information security management systems (ISMS), providing a framework for managing security, not for detailing specific adversary attack techniques and tactics.
The NIST Cybersecurity Framework provides a high-level guide for managing and reducing cybersecurity risks within an organization but does not detail specific adversary attack techniques and behaviors like MITRE ATT&CK.
Concept tested: Cybersecurity frameworks for adversary analysis
Source: learn.microsoft.com/en-us/azure/security/fundamentals/zero-trust-deployment-guide-threat-detection-mitre-att-ck
Topics
Community Discussion
No community discussion yet for this question.