nerdexam
Cisco

300-220 · Question #56

The MITRE ATT&CK framework is used to:

The correct answer is B. Model threats based on tactics, techniques, and procedures. MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a globally accessible knowledge base that catalogs real-world adversary behavior, making B correct - it lets security teams model threats by mapping attacker TTPs (tactics, techniques, and procedures)…

Threat Modeling Techniques

Question

The MITRE ATT&CK framework is used to:

Options

  • AEncrypt sensitive data
  • BModel threats based on tactics, techniques, and procedures
  • CAutomatically respond to security incidents
  • DAllocate budget for cybersecurity initiatives

How the community answered

(14 responses)
  • B
    93% (13)
  • C
    7% (1)

Explanation

MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a globally accessible knowledge base that catalogs real-world adversary behavior, making B correct - it lets security teams model threats by mapping attacker TTPs (tactics, techniques, and procedures) observed in the wild.

Why the others are wrong:

  • A is wrong because encryption is a data protection tool (think AES, TLS), not a threat modeling framework.
  • C is wrong because automated incident response belongs to SOAR platforms (e.g., Splunk SOAR, Palo Alto XSOAR) - ATT&CK is descriptive, not automated.
  • D is wrong because budget allocation is a business/governance function, unrelated to a threat intelligence framework.

Memory tip: Think of ATT&CK as a "playbook of how attackers think" - the word adversarial in the acronym is your clue that it describes attacker behavior (tactics and techniques), not defensive tooling or financial planning.

Topics

#MITRE ATT&CK#threat modeling#tactics and techniques#adversary behavior

Community Discussion

No community discussion yet for this question.

Full 300-220 Practice