300-220 · Question #109
The MITRE CAPEC database is best used for understanding:
The correct answer is B. Common attack patterns. MITRE CAPEC (Common Attack Pattern Enumeration and Classification) is a publicly maintained knowledge base specifically designed to catalog and describe common attack patterns used by adversaries. The name itself signals its purpose - it enumerates and classifies attack…
Question
The MITRE CAPEC database is best used for understanding:
Options
- ACompliance requirements
- BCommon attack patterns
- CEncryption standards
- DFirewall configurations
How the community answered
(45 responses)- A4% (2)
- B87% (39)
- C2% (1)
- D7% (3)
Explanation
MITRE CAPEC (Common Attack Pattern Enumeration and Classification) is a publicly maintained knowledge base specifically designed to catalog and describe common attack patterns used by adversaries. The name itself signals its purpose - it enumerates and classifies attack patterns, making B the direct and accurate answer.
Why the distractors are wrong:
- A (Compliance requirements): Compliance frameworks like NIST, PCI-DSS, or ISO 27001 address regulatory requirements - CAPEC has no compliance mandate function.
- C (Encryption standards): Encryption standards come from bodies like NIST or IEEE (e.g., AES, RSA) - entirely outside CAPEC's scope.
- D (Firewall configurations): Firewall rules and network configuration guidance fall under vendor docs or frameworks like CIS Benchmarks, not CAPEC.
Memory tip: Break apart the acronym - Common Attack Pattern Enumeration and Classification. Every word points to "attack patterns." If you see CAPEC on an exam, think attacker behavior and you'll never choose wrong.
Topics
Community Discussion
No community discussion yet for this question.