CompTIA CySA+ (CS0-002) Practice
Exam 4 with verified solutions
You need to perform an architectural review and select a view that focuses on the technologies,
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
settings, and configurations used within the architecture. Which of the following views
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
should you select? |||||| ||||||
A.Logical view ||||||
B.Operational view ||||||
C.Acquisition view ||||||
D.Technical view - ...,.🔹VERIFIED ANSWER **✔✔D.Technical view |||||| |||||| |||||| |||||| |||||| ||||||
(Correct)
Explanation
OBJ-2.1: A technical view focuses on technologies, settings, and configurations. An
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
operational view looks at how a function is performed or what it accomplishes. A logical view |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
describes how systems interconnect. An acquisition views focus on the procurement process.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
A technical view focuses on - ...,.🔹VERIFIED ANSWER **✔✔technologies, settings, and
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
configurations.
An operational view looks at - ...,.🔹VERIFIED ANSWER **✔✔how a function is performed
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
or what it accomplishes
|||||| |||||| ||||||
A logical view describes how - ...,.🔹VERIFIED ANSWER **✔✔systems interconnect.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
An acquisition views focus on - ...,.🔹VERIFIED ANSWER **✔✔the procurement process.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
,Dion Training wants to get an external attacker's perspective on its security status. Which of
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
the following services should they purchase?
|||||| |||||| |||||| |||||| ||||||
A.Patch management ||||||
B.Asset management ||||||
C.Vulnerability scan ||||||
D.Penetration test - ...,.🔹VERIFIED ANSWER **✔✔D.Penetration test |||||| |||||| |||||| |||||| |||||| ||||||
(Correct)
Explanation
OBJ-5.2: Penetration tests provide an organization with an external attacker's perspective on |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
their security status. The NIST process for penetration testing divides tests into four phases:
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
planning, discovery, attack, and reporting. The penetration test results are valuable security |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
planning tools, as they describe the actual vulnerabilities that an attacker might exploit to gain |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
access to a network. A vulnerability scan provides an assessment of your security posture from
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
an internal perspective. Asset management refers to a systematic approach to the governance
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
and realization of value from the things that a group or entity is responsible for over their
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
whole life cycles. It may apply both to tangible assets and intangible assets. Patch management
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
is the process that helps acquire, test, and install multiple patches (code changes) on existing
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
applications and software tools on a computer, enabling systems to stay updated on existing |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
patches and determining which patches are the appropriate ones. |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Which term is used in software development to refer to the method in which app and platform
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
updates are committed to a production environment rapidly? |||||| |||||| |||||| |||||| |||||| |||||| ||||||
A.Continuous integration ||||||
(Incorrect)
B.Continuous monitoring ||||||
C.Continuous delivery ||||||
D,Continuous deployment - ...,.🔹VERIFIED ANSWER **✔✔D,Continuous deployment |||||| |||||| |||||| |||||| |||||| ||||||
(Correct)
,Explanation
OBJ-3.4: Continuous deployment is a software development method in which app and
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
platform updates are committed to production rapidly. Continuous delivery is a software
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
development method in which app and platform requirements are frequently tested and |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
validated for immediate availability. Continuous integration is a software development |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
method in which code updates are tested and committed to development or build server/code
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
repositories rapidly. Continuous monitoring is the technique of constantly evaluating an |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
environment for changes so that new risks may be more quickly detected and business |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
operations improved upon. While continuous deployment and continuous delivery sound |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
very similar, there is one key difference. In continuous delivery, a human is still required to
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
approve the release into the production environment. In continuous deployment, the test and
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
release process into the production environment is automated, making the changes available
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
for immediate release once the code is committed.
|||||| |||||| |||||| |||||| |||||| |||||| ||||||
Continuous deployment is - ...,.🔹VERIFIED ANSWER **✔✔a software development |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
method in which app and platform updates are committed to production rapidly.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Continuous delivery is - ...,.🔹VERIFIED ANSWER **✔✔software development method in |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
which app and platform requirements are frequently tested and validated for immediate
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
availability.
Continuous integration is - ...,.🔹VERIFIED ANSWER **✔✔a software development method |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
in which code updates are tested and committed to development or build server/code
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
repositories rapidly. ||||||
Continuous monitoring is - ...,.🔹VERIFIED ANSWER **✔✔the technique of constantly |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
evaluating an environment for changes so that new risks may be more quickly detected and |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
business operations improved upon. |||||| |||||| ||||||
While continuous deployment and continuous delivery sound very similar, there -
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
...,.🔹VERIFIED ANSWER **✔✔is one key difference. In continuous delivery, a human is |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
still required to approve the release into the production environment. In continuous
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
, deployment, the test and release process into the production environment is automated, |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
making the changes available for immediate release once the code is committed.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Which analysis framework provides a graphical depiction of the attacker's approach relative to
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
a kill chain?
|||||| |||||| ||||||
A.Lockheed Martin cyber kill chain |||||| |||||| |||||| ||||||
B.Diamond Model of Intrusion Analysis |||||| |||||| |||||| ||||||
C.MITRE ATT&CK framework |||||| ||||||
D.OpenIOC - ...,.🔹VERIFIED ANSWER **✔✔B.Diamond Model of Intrusion Analysis |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
(Correct)
Explanation
OBJ-1.2: The Diamond Model provides an excellent methodology for communicating cyber |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
events and allowing analysts to derive mitigation strategies implicitly. The Diamond Model is
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
constructed around a graphical representation of an attacker's behavior. The MITRE ATT&CK |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
framework provides explicit pseudo-code examples for detecting or mitigating a given threat
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
within a network and ties specific behaviors back to individual actors. The Lockheed Martin
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
cyber kill chain provides a general life cycle description of how attacks occur but does not deal
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
with the specifics of how to mitigate them. OpenIOC contains a depth of research on APTs but
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
does not integrate the detections and mitigation strategy.
|||||| |||||| |||||| |||||| |||||| |||||| ||||||
The Diamond Model provides - ...,.🔹VERIFIED ANSWER **✔✔an excellent methodology
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
for communicating cyber events and allowing analysts to derive mitigation strategies
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
implicitly. The Diamond Model is constructed around a graphical representation of an |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
attacker's behavior. ||||||
The MITRE ATT&CK framework provides - ...,.🔹VERIFIED ANSWER **✔✔explicit
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
pseudo-code examples for detecting or mitigating a given threat within a network and ties |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
specific behaviors back to individual actors. |||||| |||||| |||||| |||||| ||||||
Exam 4 with verified solutions
You need to perform an architectural review and select a view that focuses on the technologies,
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
settings, and configurations used within the architecture. Which of the following views
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
should you select? |||||| ||||||
A.Logical view ||||||
B.Operational view ||||||
C.Acquisition view ||||||
D.Technical view - ...,.🔹VERIFIED ANSWER **✔✔D.Technical view |||||| |||||| |||||| |||||| |||||| ||||||
(Correct)
Explanation
OBJ-2.1: A technical view focuses on technologies, settings, and configurations. An
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
operational view looks at how a function is performed or what it accomplishes. A logical view |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
describes how systems interconnect. An acquisition views focus on the procurement process.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
A technical view focuses on - ...,.🔹VERIFIED ANSWER **✔✔technologies, settings, and
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
configurations.
An operational view looks at - ...,.🔹VERIFIED ANSWER **✔✔how a function is performed
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
or what it accomplishes
|||||| |||||| ||||||
A logical view describes how - ...,.🔹VERIFIED ANSWER **✔✔systems interconnect.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
An acquisition views focus on - ...,.🔹VERIFIED ANSWER **✔✔the procurement process.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
,Dion Training wants to get an external attacker's perspective on its security status. Which of
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
the following services should they purchase?
|||||| |||||| |||||| |||||| ||||||
A.Patch management ||||||
B.Asset management ||||||
C.Vulnerability scan ||||||
D.Penetration test - ...,.🔹VERIFIED ANSWER **✔✔D.Penetration test |||||| |||||| |||||| |||||| |||||| ||||||
(Correct)
Explanation
OBJ-5.2: Penetration tests provide an organization with an external attacker's perspective on |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
their security status. The NIST process for penetration testing divides tests into four phases:
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
planning, discovery, attack, and reporting. The penetration test results are valuable security |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
planning tools, as they describe the actual vulnerabilities that an attacker might exploit to gain |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
access to a network. A vulnerability scan provides an assessment of your security posture from
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
an internal perspective. Asset management refers to a systematic approach to the governance
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
and realization of value from the things that a group or entity is responsible for over their
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
whole life cycles. It may apply both to tangible assets and intangible assets. Patch management
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
is the process that helps acquire, test, and install multiple patches (code changes) on existing
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
applications and software tools on a computer, enabling systems to stay updated on existing |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
patches and determining which patches are the appropriate ones. |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Which term is used in software development to refer to the method in which app and platform
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
updates are committed to a production environment rapidly? |||||| |||||| |||||| |||||| |||||| |||||| ||||||
A.Continuous integration ||||||
(Incorrect)
B.Continuous monitoring ||||||
C.Continuous delivery ||||||
D,Continuous deployment - ...,.🔹VERIFIED ANSWER **✔✔D,Continuous deployment |||||| |||||| |||||| |||||| |||||| ||||||
(Correct)
,Explanation
OBJ-3.4: Continuous deployment is a software development method in which app and
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
platform updates are committed to production rapidly. Continuous delivery is a software
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
development method in which app and platform requirements are frequently tested and |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
validated for immediate availability. Continuous integration is a software development |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
method in which code updates are tested and committed to development or build server/code
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
repositories rapidly. Continuous monitoring is the technique of constantly evaluating an |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
environment for changes so that new risks may be more quickly detected and business |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
operations improved upon. While continuous deployment and continuous delivery sound |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
very similar, there is one key difference. In continuous delivery, a human is still required to
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
approve the release into the production environment. In continuous deployment, the test and
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
release process into the production environment is automated, making the changes available
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
for immediate release once the code is committed.
|||||| |||||| |||||| |||||| |||||| |||||| ||||||
Continuous deployment is - ...,.🔹VERIFIED ANSWER **✔✔a software development |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
method in which app and platform updates are committed to production rapidly.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Continuous delivery is - ...,.🔹VERIFIED ANSWER **✔✔software development method in |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
which app and platform requirements are frequently tested and validated for immediate
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
availability.
Continuous integration is - ...,.🔹VERIFIED ANSWER **✔✔a software development method |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
in which code updates are tested and committed to development or build server/code
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
repositories rapidly. ||||||
Continuous monitoring is - ...,.🔹VERIFIED ANSWER **✔✔the technique of constantly |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
evaluating an environment for changes so that new risks may be more quickly detected and |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
business operations improved upon. |||||| |||||| ||||||
While continuous deployment and continuous delivery sound very similar, there -
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
...,.🔹VERIFIED ANSWER **✔✔is one key difference. In continuous delivery, a human is |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
still required to approve the release into the production environment. In continuous
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
, deployment, the test and release process into the production environment is automated, |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
making the changes available for immediate release once the code is committed.
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
Which analysis framework provides a graphical depiction of the attacker's approach relative to
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
a kill chain?
|||||| |||||| ||||||
A.Lockheed Martin cyber kill chain |||||| |||||| |||||| ||||||
B.Diamond Model of Intrusion Analysis |||||| |||||| |||||| ||||||
C.MITRE ATT&CK framework |||||| ||||||
D.OpenIOC - ...,.🔹VERIFIED ANSWER **✔✔B.Diamond Model of Intrusion Analysis |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
(Correct)
Explanation
OBJ-1.2: The Diamond Model provides an excellent methodology for communicating cyber |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
events and allowing analysts to derive mitigation strategies implicitly. The Diamond Model is
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
constructed around a graphical representation of an attacker's behavior. The MITRE ATT&CK |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
framework provides explicit pseudo-code examples for detecting or mitigating a given threat
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
within a network and ties specific behaviors back to individual actors. The Lockheed Martin
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
cyber kill chain provides a general life cycle description of how attacks occur but does not deal
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
with the specifics of how to mitigate them. OpenIOC contains a depth of research on APTs but
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
does not integrate the detections and mitigation strategy.
|||||| |||||| |||||| |||||| |||||| |||||| ||||||
The Diamond Model provides - ...,.🔹VERIFIED ANSWER **✔✔an excellent methodology
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
for communicating cyber events and allowing analysts to derive mitigation strategies
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
implicitly. The Diamond Model is constructed around a graphical representation of an |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
attacker's behavior. ||||||
The MITRE ATT&CK framework provides - ...,.🔹VERIFIED ANSWER **✔✔explicit
|||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
pseudo-code examples for detecting or mitigating a given threat within a network and ties |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| |||||| ||||||
specific behaviors back to individual actors. |||||| |||||| |||||| |||||| ||||||