ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 144 - CS0-003 discussion

Report
Export

A Chief Information Security Officer wants to map all the attack vectors that the company faces each day. Which of the following recommendations should the company align their security controls around?

A.
OSSTMM
Answers
A.
OSSTMM
B.
Diamond Model Of Intrusion Analysis
Answers
B.
Diamond Model Of Intrusion Analysis
C.
OWASP
Answers
C.
OWASP
D.
MITRE ATT&CK
Answers
D.
MITRE ATT&CK
Suggested answer: D

Explanation:

The correct answer is D. MITRE ATT&CK.

MITRE ATT&CK is a framework that maps the tactics, techniques, and procedures (TTPs) of various threat actors and groups, based on real-world observations and data. MITRE ATT&CK can help a Chief

Information Security Officer (CISO) to map all the attack vectors that the company faces each day, as well as to align their security controls around the most relevant and prevalent threats. MITRE

ATT&CK can also help the CISO to assess the effectiveness and maturity of their security posture, as well as to identify and prioritize the gaps and improvements .

The other options are not the best recommendations for mapping all the attack vectors that the company faces each day. OSSTMM (Open Source Security Testing Methodology Manual) (A) is a methodology that provides guidelines and best practices for conducting security testing and auditing, but it does not map the TTPs of threat actors or groups. Diamond Model of Intrusion Analysis (B) is a model that analyzes the relationships and interactions between four elements of an intrusion:

adversary, capability, infrastructure, and victim. The Diamond Model can help understand the

characteristics and context of an intrusion, but it does not map the TTPs of threat actors or groups.

OWASP (Open Web Application Security Project) © is a project that provides resources and tools for improving the security of web applications, but it does not map the TTPs of threat actors or groups.


asked 02/10/2024
Welber Santos de Oliveira
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first