CS0-003 · Question #343
Which of the following statements best describes the MITRE ATT&CK framework?
The correct answer is C. It helps identify and stop enemy activity by highlighting the areas where an attacker functions. The MITRE ATT&CK framework provides a comprehensive knowledge base of adversary tactics and techniques, helping organizations understand how attackers operate to identify and stop their activity.
Question
Which of the following statements best describes the MITRE ATT&CK framework?
Options
- AIt provides a comprehensive method to test the security of applications.
- BIt provides threat intelligence sharing and development of action and mitigation strategies.
- CIt helps identify and stop enemy activity by highlighting the areas where an attacker functions.
- DIt tracks and understands threats and is an open-source project that evolves.
- EIt breaks down intrusions into a clearly defined sequence of phases.
How the community answered
(26 responses)- B4% (1)
- C92% (24)
- D4% (1)
Why each option
The MITRE ATT&CK framework provides a comprehensive knowledge base of adversary tactics and techniques, helping organizations understand how attackers operate to identify and stop their activity.
While ATT&CK can inform security testing by detailing attack methods, its primary purpose is not specifically a method to test the security of applications.
While ATT&CK is used for threat intelligence, its primary description is not 'threat intelligence sharing and development of action and mitigation strategies,' but rather a foundational knowledge base of adversary behaviors.
The MITRE ATT&CK framework provides a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. It serves as a comprehensive matrix for understanding how attackers operate, thereby enabling security teams to identify, prioritize, and implement defenses against specific adversarial behaviors, effectively helping to stop enemy activity by mapping out their functions.
While ATT&CK tracks and helps understand threats and is an open-source project that evolves, this statement does not fully encompass its core purpose of mapping adversary tactics and techniques for defensive actions.
The Cyber Kill Chain breaks down intrusions into a clearly defined sequence of phases; MITRE ATT&CK details the *techniques* attackers use within and across those phases, but does not primarily define the phases themselves.
Concept tested: MITRE ATT&CK framework purpose
Source: https://attack.mitre.org/
Topics
Community Discussion
No community discussion yet for this question.