Which of the following is a key principle that MITRE ATLAS shares with MITRE ATT&CK that makes both frameworks useful for defenders?
- A.A. Both frameworks are maintained exclusively by U.S. government agencies
- B.C. Both frameworks apply exclusively to network-based attacks and ignore physical security
- C.B. Both organize adversary behavior into tactics (goals) and techniques (methods), enabling threat modeling and detection engineering
- D.D. Both frameworks provide certified defensive products that guarantee protection
Why C is correct
Like ATT&CK, MITRE ATLAS organizes adversary knowledge into a structured matrix of Tactics (high-level objectives like Reconnaissance, Impact) and Techniques (specific methods to achieve those objectives). This enables defenders to map observed behaviors to known attack patterns, develop detections, perform gap analysis, and communicate about AI threats with a shared vocabulary.
Know someone studying for AI Security Fundamentals? Send them this one.