CCNP Security 300-745 SDSI Practice Test 23

CCNP Security 300-745 SDSI Practice Test 23 (Hard) - MITRE CAPEC Framework in the Security Design Lifecycle

CISCO CCNP Security Exam Logo

1 / 10

Which type of knowledge does the MITRE CAPEC (Common Attack Pattern Enumeration and Classification) framework primarily catalog?

2 / 10

Which design lifecycle activity would most directly benefit from referencing MITRE CAPEC attack patterns relevant to a system's technology stack?

3 / 10

Which design practice would most effectively use MITRE CAPEC data to inform the selection of security controls for a newly designed web application?

4 / 10

Which risk would most likely result from a design team using MITRE CAPEC data without also considering the specific context and exposure of the system being designed?

5 / 10

Which factor would most influence which specific MITRE CAPEC attack patterns a design team prioritizes when threat modeling a given system?

6 / 10

Which combination of practices would provide effective use of MITRE CAPEC within a security design lifecycle for a large enterprise developing multiple applications?

7 / 10

Which troubleshooting/process review step would be appropriate if a design team discovers, after an incident, that the attack technique used was a well-documented CAPEC pattern that was never referenced during the system's original threat modeling?

8 / 10

Which statement accurately describes the relationship between MITRE CAPEC and MITRE ATT&CK when both are used within a security design lifecycle?

9 / 10

Which combination of practices would help a design team keep its use of MITRE CAPEC current and relevant as the framework itself is updated and as the organization's systems evolve over time?

10 / 10

Which design practice would most help a design team use MITRE CAPEC to support threat modeling for a system built using an unfamiliar or emerging technology stack with limited internal expertise?

Your score is

The average score is 0%

0%