300-740 · Question #28
What is a crucial component in the MITRE ATT&CK framework?
The correct answer is A. Techniques for accessing credentials. Techniques for accessing credentials (A) is correct because MITRE ATT&CK is a knowledge base of adversary tactics, techniques, and procedures (TTPs) observed in real-world attacks - credential access is one of its 14 core tactic categories, making techniques like credential…
Question
What is a crucial component in the MITRE ATT&CK framework?
Options
- ATechniques for accessing credentials
- BIncident response workflow
- CBlueprint for a secure network architecture
- DBest practices for user access management
How the community answered
(60 responses)- A90% (54)
- B5% (3)
- C3% (2)
- D2% (1)
Explanation
Techniques for accessing credentials (A) is correct because MITRE ATT&CK is a knowledge base of adversary tactics, techniques, and procedures (TTPs) observed in real-world attacks - credential access is one of its 14 core tactic categories, making techniques like credential dumping and brute force central to the framework's purpose.
B (Incident response workflow) is wrong because ATT&CK describes attacker behavior, not defender response processes - that's the domain of frameworks like NIST SP 800-61 or PICERL.
C (Blueprint for secure network architecture) is wrong because ATT&CK is a threat intelligence and detection framework, not a network design guide - that role belongs to frameworks like NIST CSF or CIS Controls.
D (Best practices for user access management) is wrong because access management guidance comes from identity-focused standards like NIST 800-53 or ISO 27001, not ATT&CK.
Memory tip: Think of ATT&CK as the "attacker's playbook" - every entry describes something an adversary does (like stealing credentials), not something defenders build or manage.
Topics
Community Discussion
No community discussion yet for this question.