300-220 · Question #56
The MITRE ATT&CK framework is used to:
The correct answer is B. Model threats based on tactics, techniques, and procedures. MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a globally accessible knowledge base that catalogs real-world adversary behavior, making B correct - it lets security teams model threats by mapping attacker TTPs (tactics, techniques, and procedures)…
Question
The MITRE ATT&CK framework is used to:
Options
- AEncrypt sensitive data
- BModel threats based on tactics, techniques, and procedures
- CAutomatically respond to security incidents
- DAllocate budget for cybersecurity initiatives
How the community answered
(14 responses)- B93% (13)
- C7% (1)
Explanation
MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a globally accessible knowledge base that catalogs real-world adversary behavior, making B correct - it lets security teams model threats by mapping attacker TTPs (tactics, techniques, and procedures) observed in the wild.
Why the others are wrong:
- A is wrong because encryption is a data protection tool (think AES, TLS), not a threat modeling framework.
- C is wrong because automated incident response belongs to SOAR platforms (e.g., Splunk SOAR, Palo Alto XSOAR) - ATT&CK is descriptive, not automated.
- D is wrong because budget allocation is a business/governance function, unrelated to a threat intelligence framework.
Memory tip: Think of ATT&CK as a "playbook of how attackers think" - the word adversarial in the acronym is your clue that it describes attacker behavior (tactics and techniques), not defensive tooling or financial planning.
Topics
Community Discussion
No community discussion yet for this question.