300-220 · Question #139
To model threats using MITRE ATT&CK, a security team must first:
The correct answer is B. Identify relevant tactics, techniques, and procedures. Option B is correct because MITRE ATT&CK is a knowledge base of adversary behaviors organized around Tactics (goals), Techniques (methods), and Procedures (specific implementations) - collectively called TTPs. Before you can map threats to the ATT&CK matrix, you must identify…
Question
To model threats using MITRE ATT&CK, a security team must first:
Options
- ADecrypt all network traffic
- BIdentify relevant tactics, techniques, and procedures
- CPurchase the latest antivirus software
- DHire a team of hackers for penetration testing
How the community answered
(19 responses)- A11% (2)
- B84% (16)
- D5% (1)
Explanation
Option B is correct because MITRE ATT&CK is a knowledge base of adversary behaviors organized around Tactics (goals), Techniques (methods), and Procedures (specific implementations) - collectively called TTPs. Before you can map threats to the ATT&CK matrix, you must identify which TTPs are relevant to your environment, threat actors, or incident under investigation. Option A is a network security task unrelated to threat modeling with ATT&CK. Option C (buying antivirus) is a procurement/defense action, not a modeling activity. Option D (hiring hackers) describes penetration testing, which is a separate discipline - useful, but not a prerequisite for ATT&CK-based threat modeling.
Memory tip: Think of ATT&CK as a map - before you can navigate it, you need to know where you're going (relevant TTPs). You can't use a map without a destination.
Topics
Community Discussion
No community discussion yet for this question.