nerdexam
CompTIA

CS0-003 · Question #235

A Chief Information Security Officer wants to map all the attack vectors that the company faces each day. Which of the following recommendations should the company align their security controls…

The correct answer is D. MITRE ATT&CK. MITRE ATT&CK Framework MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is the correct answer because it is specifically designed as a comprehensive knowledge base that maps real-world adversary behaviors, tactics, and techniques - essentially cataloguing…

Submitted by hans_de· Mar 6, 2026Security operations

Question

A Chief Information Security Officer wants to map all the attack vectors that the company faces each day. Which of the following recommendations should the company align their security controls around?

Options

  • AOSSTMM
  • BDiamond Model of Intrusion Analysis
  • COWASP
  • DMITRE ATT&CK

How the community answered

(15 responses)
  • A
    7% (1)
  • B
    7% (1)
  • D
    87% (13)

Explanation

MITRE ATT&CK Framework

MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is the correct answer because it is specifically designed as a comprehensive knowledge base that maps real-world adversary behaviors, tactics, and techniques - essentially cataloguing the full spectrum of attack vectors that organizations face daily, making it ideal for aligning security controls.

Why the distractors are wrong:

  • OSSTMM (A) is a methodology for testing security systems (penetration testing), not a framework for mapping ongoing attack vectors to align controls
  • Diamond Model of Intrusion Analysis (B) is an analytical framework for investigating individual intrusion events after the fact, not for broadly mapping and aligning controls around attack vectors
  • OWASP (C) focuses specifically on web application security vulnerabilities, making it too narrow in scope compared to the enterprise-wide attack vector mapping the CISO needs

Memory Tip: Think "ATT&CK = Attack Map" - the name itself contains "ATT&CK," signaling it's your go-to framework when the question involves mapping how adversaries attack, and aligning defensive controls accordingly. If the question is about web apps only, think OWASP; if it's about everything, think ATT&CK.

Topics

#MITRE ATT&CK#Threat intelligence#Security frameworks#Security controls

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice