CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium
A security analyst is investigating a series of failed login attempts against an internal application. The application's logs show numerous attempts from a single IP address (192.168.1.10) using various usernames and common passwords within a short period. The application is critical, but the attempts have not yet been successful. Which of the following attack frameworks would BEST help the analyst document and understand this specific type of activity?
- ADiamond Model of Intrusion Analysis
- BMITRE ATT&CK
- CCyber Kill Chain
- DOWASP Top 10
Show answer & explanationAnswer & explanation
Correct answer: B. MITRE ATT&CK
MITRE ATT&CK focuses on adversary tactics and techniques observed in the wild. Brute-forcing login attempts is a specific technique under the 'Credential Access' tactic, making ATT&CK ideal for documenting and understanding this activity.
Why the other options are wrong
- A. The Diamond Model is for analyzing broader intrusion events and their characteristics (adversary, capability, infrastructure, victim), not specific adversary behaviors.
- C. The Cyber Kill Chain describes the high-level stages of an intrusion, but not the granular techniques used within each stage.
- D. The OWASP Top 10 lists common web application security risks (vulnerabilities), not adversary techniques used to exploit them.
MITRE ATT&CK Framework
A globally accessible knowledge base of adversary tactics and techniques based on real-world observations, used as a foundation for the development of specific threat models and methodologies.
- Organized into tactics (goals) and techniques (how to achieve goals).
- Provides common language for describing adversary actions.
- Useful for threat intelligence, detection, and analysis.
Memory trick: ATT&CK maps out how adversaries get things done.