nerdexam
EC-Council

212-82 · Question #147

A large-scale financial Institution was targeted by a sophisticated cyber-attack that resulted In substantial data leakage and financial loss. The attack was unique in its execution, involving…

The correct answer is A. MITRE ATT&CK, encompassing a wide range of tactics and techniques used in real-world attacks. To analyze a complex, multi-stage cyber-attack pattern and revise defense strategies, the MITRE ATT&CK framework is the most suitable as it catalogs adversary tactics and techniques observed in real-world attacks.

Submitted by amina.ke· Mar 6, 2026Cloud Security Operations & Incident Response

Question

A large-scale financial Institution was targeted by a sophisticated cyber-attack that resulted In substantial data leakage and financial loss. The attack was unique in its execution, involving multiple stages and techniques that evaded traditional security measures. The institution's cybersecurity team, in their post-incident analysis, discovered that the attackers followed a complex methodology aligning with a well-known hacking framework. Identifying the framework used by the attackers is crucial for the institution to revise its defense strategies. Which of the following hacking frameworks/methodologles most likely corresponds to the attack pattern observed?

Options

  • AMITRE ATT&CK, encompassing a wide range of tactics and techniques used in real-world attacks
  • BOWASP Top Ten. focusing on web application security risks
  • CISO/IEC 27001. focusing on information security management systems
  • DNIST Cybersecurity Framework, primarily used for managing cybersecurity risks

How the community answered

(26 responses)
  • A
    88% (23)
  • C
    8% (2)
  • D
    4% (1)

Why each option

To analyze a complex, multi-stage cyber-attack pattern and revise defense strategies, the MITRE ATT&CK framework is the most suitable as it catalogs adversary tactics and techniques observed in real-world attacks.

AMITRE ATT&CK, encompassing a wide range of tactics and techniques used in real-world attacksCorrect

The MITRE ATT&CK framework is a comprehensive, globally accessible knowledge base of adversary tactics and techniques based on real-world observations, making it ideal for mapping complex, multi-stage attack patterns and understanding adversary methodologies for defense strategy revision.

BOWASP Top Ten. focusing on web application security risks

The OWASP Top Ten focuses specifically on the most critical web application security risks and is not designed as a framework for analyzing sophisticated, multi-stage network attacks.

CISO/IEC 27001. focusing on information security management systems

ISO/IEC 27001 is an international standard for information security management systems (ISMS), providing a framework for managing security, not for detailing specific adversary attack techniques and tactics.

DNIST Cybersecurity Framework, primarily used for managing cybersecurity risks

The NIST Cybersecurity Framework provides a high-level guide for managing and reducing cybersecurity risks within an organization but does not detail specific adversary attack techniques and behaviors like MITRE ATT&CK.

Concept tested: Cybersecurity frameworks for adversary analysis

Source: learn.microsoft.com/en-us/azure/security/fundamentals/zero-trust-deployment-guide-threat-detection-mitre-att-ck

Topics

#Threat intelligence frameworks#MITRE ATT&CK#Cyber attack analysis#Defense strategies

Community Discussion

No community discussion yet for this question.

Full 212-82 Practice