Courseiva
Security Operations →hardMultiple Choice

CS0-003 Security Operations Practice Question

During a threat hunting engagement, an analyst creates a hypothesis based on a recent threat intelligence report about a new APT group using DLL side-loading for persistence. The analyst decides to search for processes that have loaded a known vulnerable DLL. Which framework is most appropriate to map the TTPs?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

MITRE ATT&CK

MITRE ATT&CK is the most comprehensive framework for mapping adversary TTPs, including persistence techniques like DLL side-loading (T1574.002).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Diamond Model

    Why it's wrong here

    The Diamond Model of Intrusion Analysis is designed to map individual events by establishing relationships between four core nodes: adversary, capability, infrastructure, and victim. While highly effective for tracking campaign relationships and threat actor infrastructure over time, it does not provide a comprehensive, categorized catalog of specific adversary tactics, techniques, and procedures (TTPs) needed to formulate a technique-based threat hunting hypothesis.

  • ✗

    NIST CSF

    Why it's wrong here

    The NIST Cybersecurity Framework (CSF) is a high-level governance and risk management framework organized around core functions like Identify, Protect, Detect, Respond, and Recover. It helps organizations align their security posture with business requirements and regulatory standards, but it lacks the granular, technical taxonomy of real-world adversary behaviors required to map specific threat actor techniques during a hunt.

  • ✓

    MITRE ATT&CK

    Why this is correct

    MITRE ATT&CK is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. It provides threat hunters with a highly structured, granular matrix to map specific behaviors, identify coverage gaps in telemetry, and systematically formulate hypotheses regarding how advanced persistent threats (APTs) might execute actions within an environment.

  • ✗

    Cyber Kill Chain

    Why it's wrong here

    Lockheed Martin's Cyber Kill Chain is a linear model that outlines the phases of a cyberattack from initial reconnaissance to actions on objectives. Although useful for understanding the sequential progression of an intrusion, it operates at too high a level of abstraction to serve as a detailed catalog of specific technical methods or sub-techniques used by adversaries.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.