Categorizing and Sharing Threat Actor TTPs

Answer Correct answer: B — Using the MITRE ATT&CK framework is the standard method to categorize and share threat actor TTPs with partner organizations.

A security analyst is looking for a way to categorize and share a threat actor's TTPs with colleagues at a partner organization. Which of the following would be the best method to achieve this goal?

  1. Releasing the lessons-learned report
  2. Using the MITRE ATT&CK framework Correct Answer
  3. Sharing the CVE IDs used in attacks
  4. Sending relevant log files and pcaps

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests knowledge of threat intelligence frameworks; the trap is confusing specific vulnerabilities (CVE) with behavioral tactics (ATT&CK).

The MITRE ATT&CK framework is the standard method for categorizing and sharing threat actor Tactics, Techniques, and Procedures (TTPs) across organizations. This page explains why ATT&CK is superior to CVEs or raw logs for TTP sharing.

Choosing CVE IDs because they are well-known identifiers, but they refer to software flaws rather than attacker behavior patterns.

Community Discussion (4 comments)

tolani_adetunji 👍 10
B. Using the MITRE ATT&CK framework MITRE ATT&CK provides a standardized way to categorize and share information about threat actors' Tactics, Techniques, and Procedures (TTPs). This framework would be a suitable method for a security analyst to categorize and share information about a threat actor's TTPs with colleagues at a partner organization.
salah112 👍 2 Selected: B
B. Using the MITRE ATT&CK framework The MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework is specifically designed for categorizing and sharing information about threat actor Tactics, Techniques, and Procedures (TTPs). It provides a standardized way to describe the actions and behaviors of attackers across the different stages of the cyber kill chain. Sharing threat actor TTPs using the MITRE ATT&CK framework allows security analysts to communicate effectively and ensures a common understanding of the tactics employed by the threat actor.
salah112 👍 2 Selected: B
B. Using the MITRE ATT&CK framework The best method for categorizing and sharing a threat actor's Tactics, Techniques, and Procedures (TTPs) with colleagues, especially across organizations, is to use the MITRE ATT&CK framework. ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a knowledge base that provides a comprehensive and standardized way to describe the actions and behaviors of threat actors.
Hs1208 👍 2 Selected: B
B. Using the MITRE ATT&CK framework The most effective method for categorizing and sharing a threat actor's Tactics, Techniques, and Procedures (TTPs) with colleagues, especially across different organizations, is to use the MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct answer is B, using the MITRE ATT&CK framework. ATT&CK is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. It provides a common language for describing how attackers operate, making it the ideal tool for categorizing and sharing TTPs with partner organizations. By mapping an incident to specific ATT&CK techniques, analysts can communicate precise behavioral details that are universally understood.

Why the Other Options Are Wrong

Option A, releasing a lessons-learned report, is an internal post-incident activity focused on process improvement rather than structured threat data exchange. Option C, sharing CVE IDs, identifies vulnerable software components but does not describe the methods or procedures used by the threat actor. Option D, sending log files and pcaps, shares raw evidence which requires significant effort to analyze and lacks the standardized categorization needed for efficient collaboration on TTPs.

Community Comment Notes

Community consensus strongly supports option B. Users note that MITRE ATT&CK provides a 'standardized way' to describe attacker behaviors. Comments emphasize that ATT&CK is specifically designed for this purpose, distinguishing it from other security tools.

Official Reference

Exam Strategy

When a question asks about sharing 'TTPs' or 'behavioral patterns', immediately look for MITRE ATT&CK. Do not confuse it with STIX/TAXII (which are protocols for exchanging the data) or CVEs (which are for vulnerabilities).

Frequently Asked Questions

Why not use CVE IDs for sharing TTPs?

CVEs identify specific software vulnerabilities, not the attacker's methods or behaviors (TTPs).

Is MITRE ATT&CK free to use?

Yes, the MITRE ATT&CK framework is publicly available and free to use for threat intelligence sharing.

Related Analysis

← Back to SY0-601 Study Guide