CS0-003 · Question #235
A Chief Information Security Officer wants to map all the attack vectors that the company faces each day. Which of the following recommendations should the company align their security controls…
The correct answer is D. MITRE ATT&CK. MITRE ATT&CK Framework MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is the correct answer because it is specifically designed as a comprehensive knowledge base that maps real-world adversary behaviors, tactics, and techniques - essentially cataloguing…
Question
A Chief Information Security Officer wants to map all the attack vectors that the company faces each day. Which of the following recommendations should the company align their security controls around?
Options
- AOSSTMM
- BDiamond Model of Intrusion Analysis
- COWASP
- DMITRE ATT&CK
How the community answered
(15 responses)- A7% (1)
- B7% (1)
- D87% (13)
Explanation
MITRE ATT&CK Framework
MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is the correct answer because it is specifically designed as a comprehensive knowledge base that maps real-world adversary behaviors, tactics, and techniques - essentially cataloguing the full spectrum of attack vectors that organizations face daily, making it ideal for aligning security controls.
Why the distractors are wrong:
- OSSTMM (A) is a methodology for testing security systems (penetration testing), not a framework for mapping ongoing attack vectors to align controls
- Diamond Model of Intrusion Analysis (B) is an analytical framework for investigating individual intrusion events after the fact, not for broadly mapping and aligning controls around attack vectors
- OWASP (C) focuses specifically on web application security vulnerabilities, making it too narrow in scope compared to the enterprise-wide attack vector mapping the CISO needs
Memory Tip: Think "ATT&CK = Attack Map" - the name itself contains "ATT&CK," signaling it's your go-to framework when the question involves mapping how adversaries attack, and aligning defensive controls accordingly. If the question is about web apps only, think OWASP; if it's about everything, think ATT&CK.
Topics
Community Discussion
No community discussion yet for this question.