SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisHard
A security team is using the MITRE ATT&CK framework to understand a recent advanced persistent threat (APT) campaign targeting their industry. They are focusing on how the adversary gained initial access and then moved laterally within the network. Which layer of the ATT&CK framework are they primarily examining?
- ATactics
- BMitigations
- CTechniques
- DProcedures
Show answer & explanationAnswer & explanation
Correct answer: A. Tactics
In the MITRE ATT&CK framework, 'Tactics' represent the 'why' an adversary performs an action—their high-level goals during an attack, such as 'Initial Access' or 'Lateral Movement'. Techniques describe 'how' they achieve those goals.
Why the other options are wrong
- B. Mitigations are defensive measures to prevent or detect techniques, not part of the adversary's actions.
- C. Techniques are the specific ways adversaries achieve a tactical objective (e.g., Phishing for Initial Access).
- D. Procedures are specific implementations of techniques by a particular threat actor, often involving specific tools and steps.
MITRE ATT&CK Tactics
The top-level categories in the MITRE ATT&CK framework that represent an adversary's tactical goals or 'why' they perform certain actions during an attack.
- Examples include Initial Access, Execution, Persistence, Privilege Escalation, Lateral Movement, Exfiltration.
- Each tactic contains multiple techniques.
- Provides a common language for describing adversary behavior.
Memory trick: TTP: Tactics (why), Techniques (how), Procedures (what exactly).