CS0-003 · Question #512
Which of following attack methodology frameworks should a cybersecurity analyst use to identify similar TTPs utilized by nation-state actors?
The correct answer is D. MITRE ATT&CK matrix. The MITRE ATT&CK matrix is the most appropriate framework for identifying and analyzing similar Tactics, Techniques, and Procedures (TTPs) used by various threat actors, including nation-states.
Question
Which of following attack methodology frameworks should a cybersecurity analyst use to identify similar TTPs utilized by nation-state actors?
Options
- ACyber kill chains
- BDiamond Model of Intrusion Analysis
- COWASP Testing Guide
- DMITRE ATT&CK matrix
How the community answered
(47 responses)- A2% (1)
- B6% (3)
- C4% (2)
- D87% (41)
Why each option
The MITRE ATT&CK matrix is the most appropriate framework for identifying and analyzing similar Tactics, Techniques, and Procedures (TTPs) used by various threat actors, including nation-states.
Cyber Kill Chain is a linear model that describes the stages of an attack but is less granular and comprehensive for detailing specific TTPs across different threat actors compared to ATT&CK.
The Diamond Model of Intrusion Analysis focuses on individual intrusion events by mapping adversaries, capabilities, infrastructure, and victims, rather than providing a broad catalog of TTPs for comparative analysis across different actors.
The OWASP Testing Guide is a resource for testing the security of web applications and is not an attack methodology framework for categorizing adversary TTPs.
The MITRE ATT&CK framework provides a comprehensive, globally accessible knowledge base of adversary tactics and techniques based on real-world observations. It is specifically designed to categorize and describe the TTPs used by various threat actors, including nation-state groups, making it ideal for identifying similarities in their operational methodologies.
Concept tested: Threat intelligence frameworks (MITRE ATT&CK for TTPs)
Source: https://attack.mitre.org/about/
Topics
Community Discussion
No community discussion yet for this question.