3.1 Explain concepts related to attack methodology frameworks.
Objective 3.1 sits in Incident Response and Management, which carries 20% of the CySA+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.
Objective title verbatim from the official objectives. CompTIA exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
Mapping an intrusion report to ATT&CK, an analyst asks what the difference between a tactic and a technique is. What do you say?
Correct.
Concept
The model separates an adversary's goal from the method used to reach it, so one goal can map to many methods and detections can target either layer.
Why B
ATT&CK defines tactics as the why, the reason an adversary performs an action, and techniques as the how, the way tactical goals are achieved by performing an action.
Now you: objective 3.1 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
A new SOC hire asks what MITRE ATT&CK actually is. Which description matches?
Sample question 2 of 3
An analyst reads a CTI report describing the exact command line a group used to run a scheduled task. In ATT&CK terms, what is that detail?
Sample question 3 of 3
An OT engineer asks whether ATT&CK covers industrial control systems or only corporate networks. What is the answer?
Full CySA+ question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.