In the MITRE ATT&CK framework, TTPs are mapped to:
MITRE ATT&CK maps tactics, techniques and procedures to documented real-world threat groups, satisfying the framework's purpose of describing adversary behaviour rather than isolated indicators. Each group entry links specific techniques to observed campaigns, enabling defenders to prioritise detections against actors actually targeting their sector.
Why this answer
MITRE ATT&CK maps Tactics, Techniques, and Procedures (TTPs) to specific real-world threat groups (also called Advanced Persistent Threats or APTs). Each technique page in ATT&CK lists the known threat actors that have been observed using it, allowing defenders to attribute behaviors and prioritize defenses against groups targeting their industry. This threat-group-centric mapping is what distinguishes ATT&CK from a pure technique catalog.
Exam trap
200-201 often tests the misconception that ATT&CK is a vulnerability or compliance framework, when it is actually a behavioral knowledge base whose TTPs are mapped to real-world threat groups.
How to eliminate wrong answers
Option A is wrong because vulnerability databases (such as CVE/NVD) catalog software flaws, not adversary behaviors — ATT&CK does not map TTPs to CVEs. Option B is wrong because compliance standards (PCI-DSS, HIPAA, ISO 27001) are governance frameworks, not adversary behavior repositories, and ATT&CK mappings to controls are a separate downstream exercise. Option C is wrong because network protocols (TCP, HTTP, SMB) are technical communication standards; ATT&CK techniques may abuse protocols but TTPs are not mapped to protocol specifications.