nerdexam
CompTIA

CAS-005 · Question #18

An organization is looking for gaps in its detection capabilities based on the APTs that may target the industry. Which of the following should the security analyst use to perform threat modeling?

The correct answer is A. ATT&CK. The MITRE ATT&CK framework provides a comprehensive knowledge base of adversary tactics, techniques, and procedures (TTPs) that can be used for threat modeling. It helps identify gaps in detection capabilities by mapping real-world attack behaviors specific to the industry…

Submitted by femi9· Mar 6, 2026Security Operations

Question

An organization is looking for gaps in its detection capabilities based on the APTs that may target the industry. Which of the following should the security analyst use to perform threat modeling?

Options

  • AATT&CK
  • BOWASP
  • CCAPEC
  • DSTRIDE

How the community answered

(37 responses)
  • A
    92% (34)
  • B
    5% (2)
  • D
    3% (1)

Explanation

The MITRE ATT&CK framework provides a comprehensive knowledge base of adversary tactics, techniques, and procedures (TTPs) that can be used for threat modeling. It helps identify gaps in detection capabilities by mapping real-world attack behaviors specific to the industry, making it the most relevant for the task.

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice