exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 777 discussion

Actual exam question from CompTIA's SY0-601
Question #: 777
Topic #: 1
[All SY0-601 Questions]

A security analyst is looking for a way to categorize and share a threat actor's TTPs with colleagues at a partner organization. Which of the following would be the best method to achieve this goal?

  • A. Releasing the lessons-learned report
  • B. Using the MITRE ATT&CK framework
  • C. Sharing the CVE IDs used in attacks
  • D. Sending relevant log files and pcaps
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
tolani_adetunji
Highly Voted 1 year, 5 months ago
B. Using the MITRE ATT&CK framework MITRE ATT&CK provides a standardized way to categorize and share information about threat actors' Tactics, Techniques, and Procedures (TTPs). This framework would be a suitable method for a security analyst to categorize and share information about a threat actor's TTPs with colleagues at a partner organization.
upvoted 10 times
...
salah112
Most Recent 1 year, 4 months ago
Selected Answer: B
B. Using the MITRE ATT&CK framework The MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework is specifically designed for categorizing and sharing information about threat actor Tactics, Techniques, and Procedures (TTPs). It provides a standardized way to describe the actions and behaviors of attackers across the different stages of the cyber kill chain. Sharing threat actor TTPs using the MITRE ATT&CK framework allows security analysts to communicate effectively and ensures a common understanding of the tactics employed by the threat actor.
upvoted 2 times
...
salah112
1 year, 4 months ago
Selected Answer: B
B. Using the MITRE ATT&CK framework The best method for categorizing and sharing a threat actor's Tactics, Techniques, and Procedures (TTPs) with colleagues, especially across organizations, is to use the MITRE ATT&CK framework. ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a knowledge base that provides a comprehensive and standardized way to describe the actions and behaviors of threat actors.
upvoted 2 times
...
Hs1208
1 year, 5 months ago
Selected Answer: B
B. Using the MITRE ATT&CK framework The most effective method for categorizing and sharing a threat actor's Tactics, Techniques, and Procedures (TTPs) with colleagues, especially across different organizations, is to use the MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...