ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 332 - CS0-003 discussion

Report
Export

An analyst is reviewing a dashboard from the company's SIEM and finds that an IP address known to be malicious can be tracked to numerous high-priority events in the last two hours. The dashboard indicates that these events relate to TTPs. Which of the following is the analyst most likely using?

A.

MITRE ATT&CK

Answers
A.

MITRE ATT&CK

B.

OSSTMM

Answers
B.

OSSTMM

C.

Diamond Model of Intrusion Analysis

Answers
C.

Diamond Model of Intrusion Analysis

D.

OWASP

Answers
D.

OWASP

Suggested answer: A

Explanation:

The MITRE ATT&CK framework is specifically designed for tracking Tactics, Techniques, and Procedures (TTPs) associated with cyber threats. It provides a detailed matrix of known adversarial behaviors, which is useful for correlating SIEM data to known attack patterns. According to CompTIA CySA+, MITRE ATT&CK is an industry-standard framework for threat intelligence and behavior analysis, making it the ideal tool for tracking malicious IP addresses and understanding their tactics. Other options like OSSTMM, the Diamond Model, and OWASP do not focus on TTPs as directly as MITRE ATT&CK does.

asked 17/10/2024
Ilias Akarkach
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first