CAS-004 Security Operations Practice Question
An organization is implementing a threat hunting program. The team plans to use the MITRE ATT&CK framework to structure their hunts. Which THREE of the following are core components of the ATT&CK framework? (Choose THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Procedures
ATT&CK includes tactics (the 'why'), techniques (the 'how'), and procedures (specific implementations). Indicators of compromise and CVSS scores are not part of the framework; they are separate concepts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Procedures
Why this is correct
Procedures are specific implementations of techniques.
- ✗
Indicators of compromise (IOCs)
Why it's wrong here
IOCs are not a component of ATT&CK; they are evidence of techniques.
- ✗
CVSS scores
Why it's wrong here
CVSS is a vulnerability scoring system, not part of ATT&CK.
- ✓
Tactics
Why this is correct
Tactics represent the adversary's goal.
- ✓
Techniques
Why this is correct
Techniques describe how the goal is achieved.
Go deeper
Related to this question
About these practice questions
One of 968 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.