ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 352 - CS0-003 discussion

Report
Export

Which of the following is the best framework for assessing how attackers use techniques over an infrastructure to exploit a target's information assets?

A.

Structured Threat Information Expression

Answers
A.

Structured Threat Information Expression

B.

OWASP Testing Guide

Answers
B.

OWASP Testing Guide

C.

Open Source Security Testing Methodology Manual

Answers
C.

Open Source Security Testing Methodology Manual

D.

Diamond Model of Intrusion Analysis

Answers
D.

Diamond Model of Intrusion Analysis

Suggested answer: D

Explanation:

The Diamond Model of Intrusion Analysis focuses on understanding the relationships between the adversary, their capabilities, infrastructure, and victim. It provides a structured approach to examining how attackers exploit information assets. According to CompTIA CySA+, this model is valuable for detailing attack patterns and understanding the infrastructure attackers use. The other options, like Structured Threat Information Expression (A) and OWASP Testing Guide (B), address threat data sharing and web application testing, respectively, while the Open Source Security Testing Methodology Manual (OSSTMM) (C) covers general security testing procedures.

asked 17/10/2024
Razan Althubaiti
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first