300-220 · Question #78
In the context of threat actor attribution, TTPs stand for:
The correct answer is B. Tactics, Techniques, and Procedures. TTPs stands for Tactics, Techniques, and Procedures (B) - a framework used in cybersecurity to describe and categorize the behavior of threat actors. Tactics represent the high-level goals (e.g., initial access, lateral movement), techniques are the specific methods used to…
Question
In the context of threat actor attribution, TTPs stand for:
Options
- ATools, Techniques, and Procedures
- BTactics, Techniques, and Procedures
- CTargets, Tactics, and Procedures
- DTechniques, Targets, and Programs
How the community answered
(39 responses)- A3% (1)
- B92% (36)
- D5% (2)
Explanation
TTPs stands for Tactics, Techniques, and Procedures (B) - a framework used in cybersecurity to describe and categorize the behavior of threat actors. Tactics represent the high-level goals (e.g., initial access, lateral movement), techniques are the specific methods used to achieve those goals, and procedures are the detailed, step-by-step implementations of those techniques.
Why the distractors are wrong:
- A replaces "Tactics" with "Tools" - tools are certainly part of threat analysis (e.g., in the MITRE ATT&CK framework), but the T in TTPs specifically refers to Tactics, not Tools.
- C introduces "Targets," which is not part of the acronym - targets are a separate analytical concept (who is attacked), not how the attack is carried out.
- D scrambles the order and swaps "Programs" for "Procedures" - programs is not a standard term in this threat intelligence framework.
Memory tip: Think of TTPs as a zoom-in hierarchy - Tactics (the "why/goal") → Techniques (the "how") → Procedures (the "exact steps") - going from broad strategy down to granular execution. The MITRE ATT&CK matrix is built around this exact model, so associating TTPs with ATT&CK will reinforce the correct definition.
Topics
Community Discussion
No community discussion yet for this question.