CS0-003 Security Operations Practice Question
During a threat hunting engagement, an analyst creates a hypothesis based on a recent threat intelligence report about a new APT group using DLL side-loading for persistence. The analyst decides to search for processes that have loaded a known vulnerable DLL. Which framework is most appropriate to map the TTPs?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
MITRE ATT&CK
MITRE ATT&CK is the most comprehensive framework for mapping adversary TTPs, including persistence techniques like DLL side-loading (T1574.002).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Diamond Model
Why it's wrong here
The Diamond Model of Intrusion Analysis is designed to map individual events by establishing relationships between four core nodes: adversary, capability, infrastructure, and victim. While highly effective for tracking campaign relationships and threat actor infrastructure over time, it does not provide a comprehensive, categorized catalog of specific adversary tactics, techniques, and procedures (TTPs) needed to formulate a technique-based threat hunting hypothesis.
- ✗
NIST CSF
Why it's wrong here
The NIST Cybersecurity Framework (CSF) is a high-level governance and risk management framework organized around core functions like Identify, Protect, Detect, Respond, and Recover. It helps organizations align their security posture with business requirements and regulatory standards, but it lacks the granular, technical taxonomy of real-world adversary behaviors required to map specific threat actor techniques during a hunt.
- ✓
MITRE ATT&CK
Why this is correct
MITRE ATT&CK is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. It provides threat hunters with a highly structured, granular matrix to map specific behaviors, identify coverage gaps in telemetry, and systematically formulate hypotheses regarding how advanced persistent threats (APTs) might execute actions within an environment.
- ✗
Cyber Kill Chain
Why it's wrong here
Lockheed Martin's Cyber Kill Chain is a linear model that outlines the phases of a cyberattack from initial reconnaissance to actions on objectives. Although useful for understanding the sequential progression of an intrusion, it operates at too high a level of abstraction to serve as a detailed catalog of specific technical methods or sub-techniques used by adversaries.
Go deeper
Related to this question
Learn chapter
MITRE ATT&CK Framework for SOC Analysts
Key term
MITRE ATT&CK
MITRE ATT&CK is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations, used by security professionals to understand and defend against cyber threats.
Key term
Persistence
Persistence is the set of techniques attackers use to maintain long-term access to a compromised system even after reboots or credential changes.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.