Courseiva
Security Operations →mediumMultiple Choice

CAS-004 Security Operations Practice Question

A security analyst is reviewing threat intelligence feeds and notices that a known Advanced Persistent Threat (APT) group has been using a specific technique to move laterally within networks. The analyst wants to map this technique to the MITRE ATT&CK framework. Which resource would the analyst use to find the corresponding ATT&CK technique ID?

⚠ Common exam trap

The trap is confusing ATT&CK (adversary TTPs) with CVE (vulnerabilities) or NIST SP 800-61 (IR process) — candidates must recognize that technique IDs come only from the ATT&CK framework.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

MITRE ATT&CK Navigator or website

The MITRE ATT&CK Navigator and the official ATT&CK website are the authoritative resources for mapping adversary techniques to ATT&CK technique IDs (e.g., T1021 for Remote Services). The analyst would search the technique name or tactic (Lateral Movement) to find the corresponding ID and details.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    MITRE ATT&CK Navigator or website

    Why this is correct

    The MITRE ATT&CK Navigator and website host the full technique matrix with IDs, letting the analyst map the observed lateral movement technique to its corresponding identifier. It is the authoritative source for ATT&CK technique IDs, satisfying the stem's mapping requirement.

  • ✗

    NIST SP 800-61

    Why it's wrong here

    NIST SP 800-61 defines incident response lifecycle guidance, not an adversary technique catalogue, so it contains no ATT&CK technique IDs. It is the correct reference when structuring detection, containment and recovery processes during an incident, rather than mapping observed lateral-movement behaviour.

  • ✗

    STIX/TAXII feeds

    Why it's wrong here

    STIX/TAXII is a transport format and exchange protocol for sharing threat intelligence, not a technique taxonomy, so it supplies no ATT&CK technique IDs. It is the right choice when automating ingestion of indicators between platforms, not when mapping an observed technique to the framework.

  • ✗

    CVE database

    Why it's wrong here

    CVE records catalogue publicly disclosed software vulnerabilities, not adversary tactics, so they carry no ATT&CK technique IDs. The database is the right resource when identifying a specific flaw for patching or vulnerability management, not for mapping lateral-movement behaviour observed in threat intelligence.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.