nerdexam
Cisco

300-220 · Question #78

In the context of threat actor attribution, TTPs stand for:

The correct answer is B. Tactics, Techniques, and Procedures. TTPs stands for Tactics, Techniques, and Procedures (B) - a framework used in cybersecurity to describe and categorize the behavior of threat actors. Tactics represent the high-level goals (e.g., initial access, lateral movement), techniques are the specific methods used to…

Threat Actor Attribution Techniques

Question

In the context of threat actor attribution, TTPs stand for:

Options

  • ATools, Techniques, and Procedures
  • BTactics, Techniques, and Procedures
  • CTargets, Tactics, and Procedures
  • DTechniques, Targets, and Programs

How the community answered

(39 responses)
  • A
    3% (1)
  • B
    92% (36)
  • D
    5% (2)

Explanation

TTPs stands for Tactics, Techniques, and Procedures (B) - a framework used in cybersecurity to describe and categorize the behavior of threat actors. Tactics represent the high-level goals (e.g., initial access, lateral movement), techniques are the specific methods used to achieve those goals, and procedures are the detailed, step-by-step implementations of those techniques.

Why the distractors are wrong:

  • A replaces "Tactics" with "Tools" - tools are certainly part of threat analysis (e.g., in the MITRE ATT&CK framework), but the T in TTPs specifically refers to Tactics, not Tools.
  • C introduces "Targets," which is not part of the acronym - targets are a separate analytical concept (who is attacked), not how the attack is carried out.
  • D scrambles the order and swaps "Programs" for "Procedures" - programs is not a standard term in this threat intelligence framework.

Memory tip: Think of TTPs as a zoom-in hierarchy - Tactics (the "why/goal") → Techniques (the "how") → Procedures (the "exact steps") - going from broad strategy down to granular execution. The MITRE ATT&CK matrix is built around this exact model, so associating TTPs with ATT&CK will reinforce the correct definition.

Topics

#TTP#Threat Attribution#Terminology#ATT&CK Framework

Community Discussion

No community discussion yet for this question.

Full 300-220 Practice