nerdexam
Cisco

300-220 · Question #86

MITRE CAPEC is used to prioritize attacks based on:

The correct answer is B. The complexity of attack patterns. MITRE CAPEC (Common Attack Pattern Enumeration and Classification) classifies and prioritizes attack patterns primarily by their complexity - specifically, how difficult an attack is to execute, what level of skill is required, and the technical intricacy of the pattern itself…

Threat Modeling Techniques

Question

MITRE CAPEC is used to prioritize attacks based on:

Options

  • AThe cost of potential data breaches
  • BThe complexity of attack patterns
  • CThe attacker's motivation and resources
  • DThe likelihood of detection

How the community answered

(61 responses)
  • B
    93% (57)
  • C
    5% (3)
  • D
    2% (1)

Explanation

MITRE CAPEC (Common Attack Pattern Enumeration and Classification) classifies and prioritizes attack patterns primarily by their complexity - specifically, how difficult an attack is to execute, what level of skill is required, and the technical intricacy of the pattern itself. This complexity rating helps defenders understand which attack patterns are more accessible to a broader range of adversaries and therefore warrant higher defensive priority.

Why the distractors are wrong:

  • A (cost of breaches): CAPEC is a technical classification framework, not a financial risk model - breach cost estimation belongs to frameworks like FAIR.
  • C (attacker motivation/resources): While CAPEC entries do mention prerequisites, prioritization is driven by the technical complexity of the pattern itself, not by profiling attacker intent - that's more the domain of threat intelligence.
  • D (likelihood of detection): Detection probability is addressed in frameworks like MITRE ATT&CK's visibility metrics, not in CAPEC's core classification scheme.

Memory tip: Think of CAPEC as a "recipe difficulty rating" for attacks - just as a cookbook ranks recipes by cooking complexity, CAPEC ranks attack patterns by execution complexity, helping defenders focus on the most "cookable" (accessible) attacks first.

Topics

#MITRE CAPEC#Attack Patterns#Threat Classification#Attack Complexity

Community Discussion

No community discussion yet for this question.

Full 300-220 Practice