SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisHard

A security incident response team is analyzing a series of low-level alerts that, individually, seem insignificant but collectively suggest a potential reconnaissance phase by an advanced adversary. To effectively identify and track this evolving threat, which of the following threat intelligence concepts is most beneficial for correlating these disparate events?

  1. ATactics, Techniques, and Procedures (TTPs)
  2. BSecurity Information and Event Management (SIEM)
  3. CIndicators of Compromise (IoCs)
  4. DCommon Vulnerabilities and Exposures (CVEs)
Show answer & explanation

Correct answer: A. Tactics, Techniques, and Procedures (TTPs)

TTPs (Tactics, Techniques, and Procedures) provide a framework for understanding how adversaries operate. By correlating low-level alerts against known TTPs, an analyst can connect seemingly unrelated events into a broader picture of an adversary's reconnaissance efforts and anticipate their next moves, which IoCs alone might not achieve.

Why the other options are wrong

  • B. SIEM is a tool for collecting and analyzing logs, but TTPs are the conceptual framework used within a SIEM to correlate and make sense of the data for advanced threat hunting.
  • C. IoCs are specific artifacts of a compromise; while useful, they don't provide the overarching behavioral context to connect disparate low-level reconnaissance attempts into a larger campaign.
  • D. CVEs identify specific software vulnerabilities, not adversary behaviors or patterns.

Tactics, Techniques, and Procedures (TTPs)

Describes how adversaries operate, including their high-level goals (tactics), specific methods (techniques), and particular implementations (procedures).

  • Provides a behavioral understanding of threats.
  • Helps in predicting future adversary actions.
  • Used for threat hunting, incident response, and defense-in-depth planning.

Memory trick: TTPs are the 'story' that connects the clues.

More Risk Identification, Monitoring, and Analysis questions