CompTIA SecurityX (CAS-005)Security OperationsHard
A security team is developing a threat hunting program. They want to move beyond simply reacting to alerts and proactively search for advanced persistent threats (APTs) that may have bypassed automated defenses. Which of the following methodologies emphasizes establishing hypotheses about attacker behavior and systematically searching for evidence to prove or disprove them?
- ASecurity Information and Event Management (SIEM)
- BCyber Kill Chain
- CVulnerability Management
- DMITRE ATT&CK Framework
Show answer & explanationAnswer & explanation
Correct answer: D. MITRE ATT&CK Framework
The MITRE ATT&CK Framework is specifically designed to describe and categorize adversary tactics and techniques. It provides a knowledge base that threat hunters can use to form hypotheses (e.g., 'If an APT is targeting us, they might use technique X or Y') and then search their environment for evidence of those specific techniques, making it ideal for proactive threat hunting.
Why the other options are wrong
- A. SIEM is a tool for collecting and analyzing logs, which is used *during* threat hunting, but it's not a methodology for establishing hypotheses.
- B. The Cyber Kill Chain describes the stages of an attack but doesn't provide the granular detail of attacker techniques needed for hypothesis-driven hunting.
- C. Vulnerability management focuses on identifying and remediating system weaknesses, not proactive threat hunting based on attacker behavior.
MITRE ATT&CK Framework
A globally accessible knowledge base of adversary tactics and techniques based on real-world observations. It provides a common language and framework for describing attacker behavior across the attack lifecycle.
- Organized into Tactics (goals) and Techniques (how goals are achieved).
- Used for threat hunting, red teaming, and security control mapping.
- Helps understand adversary behavior beyond just malware signatures.
Memory trick: Hunting needs a map of where the prey might hide.