nerdexam
EC-Council

312-39 · Question #32

You are working at Tech Solutions, a global technology firm. Your team detects an adversary attempting to bypass authentication controls and escalate privileges within the enterprise network. To…

The correct answer is B. MITRE D3FEND Framework. MITRE D3FEND is specifically designed to map defensive techniques to offensive adversary behaviors and tactics. In SOC and detection engineering, it provides a structured defensive ontology: you can identify an adversary technique (credential access, privilege escalation…

Threat Intelligence

Question

You are working at Tech Solutions, a global technology firm. Your team detects an adversary attempting to bypass authentication controls and escalate privileges within the enterprise network. To counter the threat, you implement credential encryption, behavioral analytics, and process isolation. Your approach follows a structured framework that systematically maps defensive techniques to known adversarial tactics, allowing you to anticipate and mitigate evolving cyber threats. Which framework did you choose to apply in this scenario?

Options

  • ASystems Security Engineering CMM
  • BMITRE D3FEND Framework
  • CCybersecurity Capability Maturity Model
  • DNIST Cybersecurity Framework 2.0

How the community answered

(36 responses)
  • A
    6% (2)
  • B
    75% (27)
  • C
    6% (2)
  • D
    14% (5)

Explanation

MITRE D3FEND is specifically designed to map defensive techniques to offensive adversary behaviors and tactics. In SOC and detection engineering, it provides a structured defensive ontology: you can identify an adversary technique (credential access, privilege escalation, defense evasion) and then select defensive countermeasures such as credential hardening, process isolation, monitoring/behavior analytics, and access control enforcement. The scenario describes a framework that “systematically maps defensive techniques to known adversarial tactics,” which aligns directly with D3FEND’s purpose. The other options are broader governance or maturity models rather than a defensive technique-mapping framework. Systems Security Engineering CMM and Cybersecurity Capability Maturity Models focus on process maturity and organizational capability development, not on mapping defensive controls to adversary behavior at a technique level. NIST CSF 2.0 is a high- level cybersecurity risk management framework organized around functions (govern, identify, protect, detect, respond, recover); it guides program structure but does not provide the same granular defensive technique taxonomy. Therefore, MITRE D3FEND is the correct choice for a structured, technique-to-defense mapping approach.

Topics

#MITRE D3FEND#defensive framework#privilege escalation#adversary mapping

Community Discussion

No community discussion yet for this question.

Full 312-39 Practice