CompTIA CySA+ (CS0-003)Security OperationsMedium

During an incident, an analyst identifies that an attacker used a phishing email for initial access, then leveraged a scheduled task for persistence, and finally used PsExec to move laterally to a file server. The analyst wants to document this behavior using a standardized adversary behavior framework for the incident report. Which framework should be used?

  1. ANIST Cybersecurity Framework (CSF)
  2. BCVSS scoring framework
  3. CMITRE ATT&CK
  4. DDiamond Model of Intrusion Analysis
Show answer & explanation

Correct answer: C. MITRE ATT&CK

MITRE ATT&CK is a knowledge base of adversary tactics and techniques (e.g., Initial Access, Persistence, Lateral Movement) used to categorize observed behaviors like phishing, scheduled tasks, and PsExec usage into standardized TTPs.

Why the other options are wrong

  • A. NIST CSF is a risk management framework (Identify, Protect, Detect, Respond, Recover), not a TTP catalog.
  • B. CVSS scores vulnerability severity, unrelated to categorizing attacker behavior.
  • D. The Diamond Model analyzes adversary, capability, infrastructure, and victim relationships, not a technique taxonomy.

MITRE ATT&CK Framework

A globally accessible knowledge base of adversary tactics and techniques based on real-world observations, used to categorize and communicate attacker behavior (TTPs).

  • Organized into tactics (the 'why') and techniques (the 'how')
  • Covers Initial Access, Execution, Persistence, Lateral Movement, etc.
  • Widely used for threat hunting, detection engineering, and reporting

Memory trick: ATT&CK = the attacker's 'playbook map' of tactics and techniques.

More Security Operations questions