Interview Flashcards
What does ATT&CK stand for?
Adversarial Tactics, Techniques, and Common Knowledge.
Who developed the MITRE ATT&CK framework?
MITRE, a nonprofit organization that conducts federally funded research.
Breakdown tactics, techniques, and procedures.
Tactics: represent the WHY of an attack.
Techniques: represent the HOW of an attack.
Sub-techniques: represent more granular details about a technique.
Procedures: represent real-world examples of adversarial implementation of tactics and techniques.
Why is the MITRE ATT&CK framework useful?
Threat intelligence, security strategy, detection and response, and adversary emulation.
What are the MITRE ATT&CK framework matrices?
Enterprise, mobile, and ICS.
What are the 12 primary tactics in the MITRE ATT&CK Enterprise Matrix and their order in a typical attack lifecycle?
1.) Initial Access
2.) Execution
3.) Persistence
4.) Privilege Escalation
5.) Defense Evasion
6.) Credential Access
7.) Discovery
8.) Lateral Movement
9.) Collection
10.) Command and Control
11.) Exfiltration
12.) Impact
How does the Lockheed Martin Cyber Kill Chain help organizations?
By detecting and stopping attacks at various stages.
What are the stages of the Lockheed Martin Cyber Kill Chain?
Reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on objectives.