ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 356 - CS0-003 discussion

Report
Export

An analyst is reviewing a dashboard from the company's SIEM and finds that an IP address known to be malicious can be tracked to numerous high-priority events in the last two hours. The dashboard indicates that these events relate to TTPs. Which of the following is the analyst most likely using?

A.

MITRE ATT&CK

Answers
A.

MITRE ATT&CK

B.

OSSTMM

Answers
B.

OSSTMM

C.

Diamond Model of Intrusion Analysis

Answers
C.

Diamond Model of Intrusion Analysis

D.

OWASP

Answers
D.

OWASP

Suggested answer: A

Explanation:

The MITRE ATT&CK framework is widely used for tracking and categorizing Tactics, Techniques, and Procedures (TTPs) of adversaries. TTPs help analysts understand the behaviors and methods attackers employ during incidents, making this framework particularly useful in SIEM dashboards for correlating and identifying threats. While the other options (OSSTMM, Diamond Model, OWASP) offer various security methodologies, MITRE ATT&CK is specifically focused on documenting adversary behaviors, making it the best fit here. CompTIA CySA+ often emphasizes MITRE ATT&CK for mapping and understanding threat behaviors in incident response.

asked 17/10/2024
Istvan Molnar
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first