Categorizing and Sharing Threat Actor TTPs
A security analyst is looking for a way to categorize and share a threat actor's TTPs with colleagues at a partner organization. Which of the following would be the best method to achieve this goal?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests knowledge of threat intelligence frameworks; the trap is confusing specific vulnerabilities (CVE) with behavioral tactics (ATT&CK).
The MITRE ATT&CK framework is the standard method for categorizing and sharing threat actor Tactics, Techniques, and Procedures (TTPs) across organizations. This page explains why ATT&CK is superior to CVEs or raw logs for TTP sharing.
Choosing CVE IDs because they are well-known identifiers, but they refer to software flaws rather than attacker behavior patterns.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The correct answer is B, using the MITRE ATT&CK framework. ATT&CK is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. It provides a common language for describing how attackers operate, making it the ideal tool for categorizing and sharing TTPs with partner organizations. By mapping an incident to specific ATT&CK techniques, analysts can communicate precise behavioral details that are universally understood.Why the Other Options Are Wrong
Option A, releasing a lessons-learned report, is an internal post-incident activity focused on process improvement rather than structured threat data exchange. Option C, sharing CVE IDs, identifies vulnerable software components but does not describe the methods or procedures used by the threat actor. Option D, sending log files and pcaps, shares raw evidence which requires significant effort to analyze and lacks the standardized categorization needed for efficient collaboration on TTPs.Community Comment Notes
Community consensus strongly supports option B. Users note that MITRE ATT&CK provides a 'standardized way' to describe attacker behaviors. Comments emphasize that ATT&CK is specifically designed for this purpose, distinguishing it from other security tools.Official Reference
Exam Strategy
When a question asks about sharing 'TTPs' or 'behavioral patterns', immediately look for MITRE ATT&CK. Do not confuse it with STIX/TAXII (which are protocols for exchanging the data) or CVEs (which are for vulnerabilities).
Frequently Asked Questions
Why not use CVE IDs for sharing TTPs?
CVEs identify specific software vulnerabilities, not the attacker's methods or behaviors (TTPs).
Is MITRE ATT&CK free to use?
Yes, the MITRE ATT&CK framework is publicly available and free to use for threat intelligence sharing.