CS0-004 - Incident Response and Management - Section 3.1

Summarize concepts related to attack methodology frameworks.

Summarise the frameworks analysts use to structure an intrusion - MITRE ATT&CK, the Cyber Kill Chain, and the Diamond Model - and explain how mapping observed activity to a framework supports detection, gap analysis and response. Recognise what each framework describes and where it is most useful.

MITRE ATT&CKCyber Kill ChainDiamond Modeltactics and techniques mappingdetection gap analysis

Practice question for this objective

Free sampleIncident Response and Managementmedium

An analyst maps existing detection rules against the MITRE ATT&CK matrix and marks techniques with no corresponding rule. What is this practice called and what does it reveal?

  • APenetration testing, which reveals whether the analyst can exploit each mapped technique in production.
  • BDetection gap analysis, which reveals adversary techniques the current tooling would fail to observe. Correct
  • CRisk acceptance, which reveals the residual likelihood remaining after all controls are applied.
  • DBaseline configuration, which reveals the approved settings each monitored asset should hold.
Recognise detection gap analysis as mapping detection coverage to ATT&CK to expose unmonitored techniques. Overlaying current detections onto the ATT&CK matrix produces a coverage heat map, and the unshaded techniques mark behaviours that would proceed unnoticed, which is the output detection gap analysis is designed to give.

Why A is wrong: Testing controls is related work, but exploiting techniques is an offensive activity distinct from mapping detection coverage.

Why B is correct: Correct: mapping coverage to ATT&CK surfaces the techniques lacking detection, which is precisely detection gap analysis.

Why C is wrong: Residual risk is a real governance concept, yet it describes a decision about risk rather than the coverage-mapping exercise here.

Why D is wrong: Baselines matter for drift detection, but they document approved states rather than gaps in behavioural detection coverage.

See more CS0-004 practice questions, answers explained.

More in this domain

Back to all Incident Response and Management objectives, or the CS0-004 cert hub.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.