nerdexam
Cisco

300-220 · Question #43

The MITRE ATT&CK framework is primarily used for modeling:

The correct answer is C. Threats using tactics, techniques, and procedures. MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a globally accessible knowledge base specifically designed to document and categorize how real-world adversaries behave - making option C correct. It organizes threat actor behavior into tactics (the…

Threat Modeling Techniques

Question

The MITRE ATT&CK framework is primarily used for modeling:

Options

  • ABusiness processes
  • BPhysical security measures
  • CThreats using tactics, techniques, and procedures
  • DSoftware development lifecycles

How the community answered

(62 responses)
  • A
    3% (2)
  • B
    5% (3)
  • C
    90% (56)
  • D
    2% (1)

Explanation

MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a globally accessible knowledge base specifically designed to document and categorize how real-world adversaries behave - making option C correct. It organizes threat actor behavior into tactics (the "why"), techniques (the "how"), and procedures (specific implementations), giving defenders a common language to describe, detect, and respond to attacks. Options A and D are wrong because ATT&CK is not a business or software process framework - those domains belong to tools like BPMN or SDLC methodologies. Option B is wrong because ATT&CK focuses entirely on cyber/digital threats, not locks, cameras, or physical access controls.

Memory tip: Think of ATT&CK as an adversary's playbook - it literally catalogues what attackers do and how they do it, which is the definition of TTPs (Tactics, Techniques, and Procedures).

Topics

#MITRE ATT&CK#Threat Modeling#TTPs#Attack Framework

Community Discussion

No community discussion yet for this question.

Full 300-220 Practice