nerdexam
Cisco

300-220 · Question #139

To model threats using MITRE ATT&CK, a security team must first:

The correct answer is B. Identify relevant tactics, techniques, and procedures. Option B is correct because MITRE ATT&CK is a knowledge base of adversary behaviors organized around Tactics (goals), Techniques (methods), and Procedures (specific implementations) - collectively called TTPs. Before you can map threats to the ATT&CK matrix, you must identify…

Threat Modeling Techniques

Question

To model threats using MITRE ATT&CK, a security team must first:

Options

  • ADecrypt all network traffic
  • BIdentify relevant tactics, techniques, and procedures
  • CPurchase the latest antivirus software
  • DHire a team of hackers for penetration testing

How the community answered

(19 responses)
  • A
    11% (2)
  • B
    84% (16)
  • D
    5% (1)

Explanation

Option B is correct because MITRE ATT&CK is a knowledge base of adversary behaviors organized around Tactics (goals), Techniques (methods), and Procedures (specific implementations) - collectively called TTPs. Before you can map threats to the ATT&CK matrix, you must identify which TTPs are relevant to your environment, threat actors, or incident under investigation. Option A is a network security task unrelated to threat modeling with ATT&CK. Option C (buying antivirus) is a procurement/defense action, not a modeling activity. Option D (hiring hackers) describes penetration testing, which is a separate discipline - useful, but not a prerequisite for ATT&CK-based threat modeling.

Memory tip: Think of ATT&CK as a map - before you can navigate it, you need to know where you're going (relevant TTPs). You can't use a map without a destination.

Topics

#MITRE ATT&CK framework#threat modeling#tactics and techniques#threat analysis

Community Discussion

No community discussion yet for this question.

Full 300-220 Practice