GSEC · Question #274
Which of the following resources is a knowledge base of real-world observed adversary tactics and techniques?
The correct answer is B. MITRE ATT&CK. MITRE ATT&CK is the industry-recognized knowledge base documenting real-world adversary tactics, techniques, and procedures (TTPs) observed in actual attacks.
Question
Which of the following resources is a knowledge base of real-world observed adversary tactics and techniques?
Options
- ALockheed Martin Cyber Kill Chain
- BMITRE ATT&CK
- CCIS Controls
- DNIST Framework
How the community answered
(44 responses)- A11% (5)
- B80% (35)
- C7% (3)
- D2% (1)
Why each option
MITRE ATT&CK is the industry-recognized knowledge base documenting real-world adversary tactics, techniques, and procedures (TTPs) observed in actual attacks.
The Lockheed Martin Cyber Kill Chain is a model describing the sequential stages of a cyberattack lifecycle, not a knowledge base of specific observed adversary techniques.
MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a globally accessible, curated knowledge base built from real-world threat intelligence and observed adversary behavior. It categorizes attack behaviors into tactics and techniques, enabling defenders to map threats and improve detection coverage. Unlike frameworks focused on process or controls, ATT&CK is specifically a repository of empirically observed attacker behavior.
CIS Controls is a set of prioritized cybersecurity best practice recommendations for organizations to implement defensively, not a knowledge base of adversary behavior.
The NIST Cybersecurity Framework provides guidance for managing and reducing organizational cybersecurity risk through structured standards and practices, not a repository of observed attacker TTPs.
Concept tested: MITRE ATT&CK framework for adversary TTPs
Source: https://attack.mitre.org/
Topics
Community Discussion
No community discussion yet for this question.