ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 590 - SY0-601 discussion

Report
Export

A security analyst has been reading about a newly discovered cyberattack from a known threat actor Which of the following would best support the analyst's review of the tactics, techniques, and protocols the throat actor was observed using in previous campaigns?

A.
Security research publications
Answers
A.
Security research publications
B.
The MITRE ATT4CK framework
Answers
B.
The MITRE ATT4CK framework
C.
The Diamond Model of Intrusion Analysis
Answers
C.
The Diamond Model of Intrusion Analysis
D.
The Cyber Kill Cham
Answers
D.
The Cyber Kill Cham
Suggested answer: B

Explanation:

The MITRE ATT&CK framework would best support the analyst's review of the tactics, techniques, and procedures (TTPs) the threat actor was observed using in previous campaigns. The MITRE ATT&CK framework is a knowledge base that describes the common TTPs used by various threat actors across different stages of an attack lifecycle. The framework can help security analysts understand how adversaries operate, what tools they use, what vulnerabilities they exploit, what indicators they leave behind, etc. The framework can also help security analysts improve their detection and response capabilities by providing recommendations and best practices.

asked 02/10/2024
Amil Akhundzada
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first