ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 293 - CAS-004 discussion

Report
Export

A security analyst for a managed service provider wants to implement the most up-to-date and effective security methodologies to provide clients with the best offerings. Which of the following resources would the analyst MOST likely adopt?

A.
OSINT
Answers
A.
OSINT
B.
ISO
Answers
B.
ISO
C.
MITRE ATT&CK
Answers
C.
MITRE ATT&CK
D.
OWASP
Answers
D.
OWASP
Suggested answer: C

Explanation:

MITRE ATT&CK is a threat management framework that provides a comprehensive and detailed knowledge base of adversary tactics and techniques based on real-world observations. It can help security analysts to identify, understand, and prioritize potential threats, as well as to develop effective detection and response strategies. MITRE ATT&CK covers the entire lifecycle of a cyberattack, from initial access to impact, and provides information on how to mitigate, detect, and hunt for each technique. It also includes threat actor profiles, software descriptions, and data sources that can be used for threat intelligence and analysis. MITRE ATT&CK is the most likely resource that a security analyst would adopt to implement the most up-to-date and effective security methodologies for their clients. Verified

Reference:

https://attack.mitre.org/

https://resources.infosecinstitute.com/topic/top-threat-modeling-frameworks-stride-owasp-top-10-mitre-attck-framework/

asked 02/10/2024
Sam Patel
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first