Interview Flashcards

1
Q

What does ATT&CK stand for?

A

Adversarial Tactics, Techniques, and Common Knowledge.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Who developed the MITRE ATT&CK framework?

A

MITRE, a nonprofit organization that conducts federally funded research.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Breakdown tactics, techniques, and procedures.

A

Tactics: represent the WHY of an attack.
Techniques: represent the HOW of an attack.
Sub-techniques: represent more granular details about a technique.
Procedures: represent real-world examples of adversarial implementation of tactics and techniques.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Why is the MITRE ATT&CK framework useful?

A

Threat intelligence, security strategy, detection and response, and adversary emulation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the MITRE ATT&CK framework matrices?

A

Enterprise, mobile, and ICS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the 12 primary tactics in the MITRE ATT&CK Enterprise Matrix and their order in a typical attack lifecycle?

A

1.) Initial Access
2.) Execution
3.) Persistence
4.) Privilege Escalation
5.) Defense Evasion
6.) Credential Access
7.) Discovery
8.) Lateral Movement
9.) Collection
10.) Command and Control
11.) Exfiltration
12.) Impact

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How does the Lockheed Martin Cyber Kill Chain help organizations?

A

By detecting and stopping attacks at various stages.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the stages of the Lockheed Martin Cyber Kill Chain?

A

Reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on objectives.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly