SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisHard
A security incident response team is analyzing a series of low-level alerts that, individually, seem insignificant but collectively suggest a potential reconnaissance phase by an advanced adversary. To effectively identify and track this evolving threat, which of the following threat intelligence concepts is most beneficial for correlating these disparate events?
- ATactics, Techniques, and Procedures (TTPs)
- BSecurity Information and Event Management (SIEM)
- CIndicators of Compromise (IoCs)
- DCommon Vulnerabilities and Exposures (CVEs)
Show answer & explanationAnswer & explanation
Correct answer: A. Tactics, Techniques, and Procedures (TTPs)
TTPs (Tactics, Techniques, and Procedures) provide a framework for understanding how adversaries operate. By correlating low-level alerts against known TTPs, an analyst can connect seemingly unrelated events into a broader picture of an adversary's reconnaissance efforts and anticipate their next moves, which IoCs alone might not achieve.
Why the other options are wrong
- B. SIEM is a tool for collecting and analyzing logs, but TTPs are the conceptual framework used within a SIEM to correlate and make sense of the data for advanced threat hunting.
- C. IoCs are specific artifacts of a compromise; while useful, they don't provide the overarching behavioral context to connect disparate low-level reconnaissance attempts into a larger campaign.
- D. CVEs identify specific software vulnerabilities, not adversary behaviors or patterns.
Tactics, Techniques, and Procedures (TTPs)
Describes how adversaries operate, including their high-level goals (tactics), specific methods (techniques), and particular implementations (procedures).
- Provides a behavioral understanding of threats.
- Helps in predicting future adversary actions.
- Used for threat hunting, incident response, and defense-in-depth planning.
Memory trick: TTPs are the 'story' that connects the clues.