exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 258 discussion

Actual exam question from CompTIA's CAS-004
Question #: 258
Topic #: 1
[All CAS-004 Questions]

A security analyst for a managed service provider wants to implement the most up-to-date and effective security methodologies to provide clients with the best offerings. Which of the following resources would the analyst MOST likely adopt?

  • A. OSINT
  • B. ISO
  • C. MITRE ATT&CK
  • D. OWASP
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
talosDevbot
Highly Voted 1 year, 3 months ago
Selected Answer: B
Answer has to be ISO. Key phrase in the question: "security methodologies". Examples) ISO27001: Information Security Management System (ISMS), ISO/IEC 27005: Information Security Risk Management. MITRE ATT&CK is a knowledge base of adversary tactics and techniques.
upvoted 6 times
armid
10 months, 1 week ago
what about the second keyword - most up-to-date :P
upvoted 1 times
...
...
nuel_12
Highly Voted 1 year, 5 months ago
Selected Answer: C
ISO is more broad, Mitre will focus on the TTP to defend your enterprise and is a tool mostly use by cybersecurity.
upvoted 5 times
...
Steel16
Most Recent 2 months, 2 weeks ago
Selected Answer: C
MITRE ATT&CK is generally considered more effective than ISO standards because it provides a detailed, real-time view of attacker tactics, techniques, and procedures (TTPs), enabling more targeted defense strategies compared to the broader, compliance-focused ISO guidelines.
upvoted 1 times
...
HereToStudy
8 months ago
Selected Answer: B
ISO standards are reviewed and updated regularly.
upvoted 1 times
...
EAlonso
10 months ago
B, as ISO is a methodology, MITRE is a framework.
upvoted 1 times
...
ninjachuleta
10 months, 4 weeks ago
Selected Answer: C
C. MITRE ATT&CK
upvoted 2 times
...
e020fdc
1 year, 2 months ago
Selected Answer: C
From the MITRE Corporation website: "MITRE ATT&CK® is a knowledge base that helps model cyber adversaries' tactics and techniques—and then shows how to detect or stop them." So this would satisfy the need for methodologies for the security analyst. Also, they are more up-to-date than ISO. ISO does focus on security too, but they review their standards every 5 years.
upvoted 4 times
...
ThatGuyOverThere
1 year, 6 months ago
Selected Answer: B
I'm going with B since ISO releases standards specific to helping with strengthening cybersecurity posture. MITRE is more about detailing tactics of adversaries. MITRE can help see what types of attacks need to be defended against, but ISO standards would be more specific to building a strong cybersecurity posture.
upvoted 3 times
...
last_resort
2 years, 1 month ago
This one is weird. I guess it should be MITRE but only because the others don't really make sense...OWASP is for web applications, OSINT is open source intelligence gathering and ISO is for standardization.
upvoted 4 times
...
Geofab
2 years, 1 month ago
Selected Answer: C
I believe the answer is C. I was going back and forth between MITRE and OWASP, but after reading what the official Comptia study guide said regarding the 2, I chose MITRE
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago