CAS-005 · Question #417
A SOC team receives notifications that align with playbook incidents. The team wants to analyze the potential threat actor's TTPs. Which of the following will best assist the SOC team?
The correct answer is C. ATT&CK. The MITRE ATT&CK framework is explicitly designed to catalog and map adversary Tactics, Techniques, and Procedures (TTPs). By correlating your SOC alerts with ATT&CK’s matrix, you can profile likely threat actors, anticipate their next moves, and tailor your detection and…
Question
A SOC team receives notifications that align with playbook incidents. The team wants to analyze the potential threat actor’s TTPs. Which of the following will best assist the SOC team?
Options
- AD3FEND
- BOWASP
- CATT&CK
- DCOPPA
- ECAPEC
How the community answered
(35 responses)- A3% (1)
- B6% (2)
- C89% (31)
- D3% (1)
Explanation
The MITRE ATT&CK framework is explicitly designed to catalog and map adversary Tactics, Techniques, and Procedures (TTPs). By correlating your SOC alerts with ATT&CK’s matrix, you can profile likely threat actors, anticipate their next moves, and tailor your detection and response strategies accordingly.
Community Discussion
No community discussion yet for this question.