exam questions

Exam CS0-003 All Questions

View all questions & answers for the CS0-003 exam

Exam CS0-003 topic 1 question 51 discussion

Actual exam question from CompTIA's CS0-003
Question #: 51
Topic #: 1
[All CS0-003 Questions]

Which of the following would a security analyst most likely use to compare TTPs between different known adversaries of an organization?

  • A. MITRE ATT&CK
  • B. Cyber Kill Cham
  • C. OWASP
  • D. STIX/TAXII
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kmordalv
Highly Voted 1 year, 1 month ago
Selected Answer: A
MITRE ATT&CK that provides a standardized way to describe and compare the Tactics, Techniques, and Procedures (TTPs) used by various adversaries or threat actors.
upvoted 6 times
...
nmap_king_22
Highly Voted 1 year, 1 month ago
Selected Answer: A
A security analyst would most likely use: A. MITRE ATT&CK MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a widely used framework that provides a comprehensive matrix of known Tactics, Techniques, and Procedures (TTPs) used by various adversaries. It allows security analysts to compare and map the TTPs observed in their environment to those associated with known threat actors and groups. By using ATT&CK, analysts can gain insights into which adversaries may be responsible for specific incidents based on their TTPs, aiding in threat intelligence analysis and incident response
upvoted 5 times
...
RobV
Most Recent 10 months, 2 weeks ago
Selected Answer: A
A. MITRE ATT&CK
upvoted 1 times
...
Alizade
11 months, 2 weeks ago
Selected Answer: A
The answer is A. MITRE ATT&CK.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago