CEH v13 · 20 official modules

All 5,000 CEH questions.

Search original practice content, filter by EC-Council module or exam domain, and open any question in revision mode.

0 answered overall

Showing 2,501–2,550 of 5,000 matching questions

50 per page
2501
Module 7 · Foundation Domain 1 · Background computer worm Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2501), which action most directly controls the risk related to "computer worm"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Place preventive and detective controls across multiple stages of the chain.
  4. Patch exposed services and segment networks to restrict lateral spread.
Practice
2502
Module 7 · Foundation Domain 1 · Background computer worm Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2502), which action most directly controls the risk related to "computer worm"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Patch exposed services and segment networks to restrict lateral spread.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice
2503
Module 7 · Foundation Domain 1 · Background computer worm Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2503), which action most directly controls the risk related to "computer worm"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Patch exposed services and segment networks to restrict lateral spread.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
2504
Module 7 · Applied Domain 1 · Background computer worm Unanswered

During a financial-services purple-team test (FIN-PT-M07-2504), which action most directly controls the risk related to "computer worm"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map each asset and threat to confidentiality, integrity, and availability requirements.
  3. Patch exposed services and segment networks to restrict lateral spread.
  4. Map controls and detections to relevant ATT&CK techniques and validate coverage.
Practice
2505
Module 7 · Applied Domain 1 · Background computer worm Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2505), which action most directly controls the risk related to "computer worm"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Map each asset and threat to confidentiality, integrity, and availability requirements.
  4. Patch exposed services and segment networks to restrict lateral spread.
Practice
2506
Module 7 · Applied Domain 1 · Background computer worm Unanswered

During a government risk-validation project (GOV-RISK-M07-2506), which action most directly controls the risk related to "computer worm"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Patch exposed services and segment networks to restrict lateral spread.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice
2507
Module 7 · Applied Domain 1 · Background computer worm Unanswered

During an e-commerce application review (ECOM-WEB-M07-2507), which action most directly controls the risk related to "computer worm"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Patch exposed services and segment networks to restrict lateral spread.
  3. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
2508
Module 7 · Advanced Domain 1 · Background computer worm Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2508), which action most directly controls the risk related to "computer worm"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map each asset and threat to confidentiality, integrity, and availability requirements.
  3. Patch exposed services and segment networks to restrict lateral spread.
  4. Map controls and detections to relevant ATT&CK techniques and validate coverage.
Practice
2509
Module 7 · Advanced Domain 1 · Background computer worm Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2509), which action most directly controls the risk related to "computer worm"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Place preventive and detective controls across multiple stages of the chain.
  4. Patch exposed services and segment networks to restrict lateral spread.
Practice
2510
Module 7 · Advanced Domain 1 · Background computer worm Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2510), which action most directly controls the risk related to "computer worm"?

View answer choices
  1. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  2. Patch exposed services and segment networks to restrict lateral spread.
  3. Map each asset and threat to confidentiality, integrity, and availability requirements.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
2511
Module 7 · Foundation Domain 1 · Background computer worm Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2511), which evidence best supports an assessment of "computer worm"?

View answer choices
  1. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. Repeated exploit traffic and similar infections appearing across multiple hosts.
  4. A risk register linking assets to CIA impact ratings.
Practice
2512
Module 7 · Foundation Domain 1 · Background computer worm Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2512), which evidence best supports an assessment of "computer worm"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. Repeated exploit traffic and similar infections appearing across multiple hosts.
Practice
2513
Module 7 · Foundation Domain 1 · Background computer worm Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2513), which evidence best supports an assessment of "computer worm"?

View answer choices
  1. Repeated exploit traffic and similar infections appearing across multiple hosts.
  2. A risk register linking assets to CIA impact ratings.
  3. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
2514
Module 7 · Applied Domain 1 · Background computer worm Unanswered

During a financial-services purple-team test (FIN-PT-M07-2514), which evidence best supports an assessment of "computer worm"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. Repeated exploit traffic and similar infections appearing across multiple hosts.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
2515
Module 7 · Applied Domain 1 · Background computer worm Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2515), which evidence best supports an assessment of "computer worm"?

View answer choices
  1. Repeated exploit traffic and similar infections appearing across multiple hosts.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. A risk register linking assets to CIA impact ratings.
Practice
2516
Module 7 · Applied Domain 1 · Background computer worm Unanswered

During a government risk-validation project (GOV-RISK-M07-2516), which evidence best supports an assessment of "computer worm"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. Repeated exploit traffic and similar infections appearing across multiple hosts.
Practice
2517
Module 7 · Applied Domain 1 · Background computer worm Unanswered

During an e-commerce application review (ECOM-WEB-M07-2517), which evidence best supports an assessment of "computer worm"?

View answer choices
  1. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  2. A risk register linking assets to CIA impact ratings.
  3. Repeated exploit traffic and similar infections appearing across multiple hosts.
  4. A detection matrix showing covered and uncovered ATT&CK techniques.
Practice
2518
Module 7 · Advanced Domain 1 · Background computer worm Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2518), which evidence best supports an assessment of "computer worm"?

View answer choices
  1. A risk register linking assets to CIA impact ratings.
  2. Repeated exploit traffic and similar infections appearing across multiple hosts.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
Practice
2519
Module 7 · Advanced Domain 1 · Background computer worm Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2519), which evidence best supports an assessment of "computer worm"?

View answer choices
  1. Repeated exploit traffic and similar infections appearing across multiple hosts.
  2. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  3. A detection matrix showing covered and uncovered ATT&CK techniques.
  4. A risk register linking assets to CIA impact ratings.
Practice
2520
Module 7 · Advanced Domain 1 · Background computer worm Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2520), which evidence best supports an assessment of "computer worm"?

View answer choices
  1. Telemetry mapped to reconnaissance, delivery, exploitation, installation, command and control, and objectives.
  2. A detection matrix showing covered and uncovered ATT&CK techniques.
  3. A risk register linking assets to CIA impact ratings.
  4. Repeated exploit traffic and similar infections appearing across multiple hosts.
Practice
2521
Module 7 · Foundation Domain 1 · Background malware Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2521), which statement most accurately defines "malware"?

View answer choices
  1. Software intentionally designed to disrupt, damage, spy on, or gain unauthorized control of systems.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. A knowledge base that organizes adversary tactics and techniques from observed behavior.
Practice
2522
Module 7 · Foundation Domain 1 · Background malware Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2522), which statement most accurately defines "malware"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. Software intentionally designed to disrupt, damage, spy on, or gain unauthorized control of systems.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
2523
Module 7 · Foundation Domain 1 · Background malware Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2523), which statement most accurately defines "malware"?

View answer choices
  1. Software intentionally designed to disrupt, damage, spy on, or gain unauthorized control of systems.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice
2524
Module 7 · Applied Domain 1 · Background malware Unanswered

During a financial-services purple-team test (FIN-PT-M07-2524), which statement most accurately defines "malware"?

View answer choices
  1. A staged model describing adversary activity from reconnaissance through actions on objectives.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. Software intentionally designed to disrupt, damage, spy on, or gain unauthorized control of systems.
Practice
2525
Module 7 · Applied Domain 1 · Background malware Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2525), which statement most accurately defines "malware"?

View answer choices
  1. Software intentionally designed to disrupt, damage, spy on, or gain unauthorized control of systems.
  2. The confidentiality, integrity, and availability objectives used to reason about information security.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. A knowledge base that organizes adversary tactics and techniques from observed behavior.
Practice
2526
Module 7 · Applied Domain 1 · Background malware Unanswered

During a government risk-validation project (GOV-RISK-M07-2526), which statement most accurately defines "malware"?

View answer choices
  1. The confidentiality, integrity, and availability objectives used to reason about information security.
  2. Software intentionally designed to disrupt, damage, spy on, or gain unauthorized control of systems.
  3. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  4. A staged model describing adversary activity from reconnaissance through actions on objectives.
Practice
2527
Module 7 · Applied Domain 1 · Background malware Unanswered

During an e-commerce application review (ECOM-WEB-M07-2527), which statement most accurately defines "malware"?

View answer choices
  1. Software intentionally designed to disrupt, damage, spy on, or gain unauthorized control of systems.
  2. A staged model describing adversary activity from reconnaissance through actions on objectives.
  3. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice
2528
Module 7 · Advanced Domain 1 · Background malware Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2528), which statement most accurately defines "malware"?

View answer choices
  1. A staged model describing adversary activity from reconnaissance through actions on objectives.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. The confidentiality, integrity, and availability objectives used to reason about information security.
  4. Software intentionally designed to disrupt, damage, spy on, or gain unauthorized control of systems.
Practice
2529
Module 7 · Advanced Domain 1 · Background malware Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2529), which statement most accurately defines "malware"?

View answer choices
  1. Software intentionally designed to disrupt, damage, spy on, or gain unauthorized control of systems.
  2. The confidentiality, integrity, and availability objectives used to reason about information security.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. A knowledge base that organizes adversary tactics and techniques from observed behavior.
Practice
2530
Module 7 · Advanced Domain 1 · Background malware Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2530), which statement most accurately defines "malware"?

View answer choices
  1. Software intentionally designed to disrupt, damage, spy on, or gain unauthorized control of systems.
  2. A knowledge base that organizes adversary tactics and techniques from observed behavior.
  3. A staged model describing adversary activity from reconnaissance through actions on objectives.
  4. The confidentiality, integrity, and availability objectives used to reason about information security.
Practice
2531
Module 7 · Foundation Domain 1 · Background malware Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2531), which risk is most directly associated with "malware"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Malware can steal data, establish persistence, spread, or degrade operations.
  3. Unmapped detections can leave important adversary techniques without coverage.
  4. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
Practice
2532
Module 7 · Foundation Domain 1 · Background malware Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2532), which risk is most directly associated with "malware"?

View answer choices
  1. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  2. A control focused on only one objective can leave the other security objectives exposed.
  3. Malware can steal data, establish persistence, spread, or degrade operations.
  4. Unmapped detections can leave important adversary techniques without coverage.
Practice
2533
Module 7 · Foundation Domain 1 · Background malware Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2533), which risk is most directly associated with "malware"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. Malware can steal data, establish persistence, spread, or degrade operations.
Practice
2534
Module 7 · Applied Domain 1 · Background malware Unanswered

During a financial-services purple-team test (FIN-PT-M07-2534), which risk is most directly associated with "malware"?

View answer choices
  1. Malware can steal data, establish persistence, spread, or degrade operations.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
2535
Module 7 · Applied Domain 1 · Background malware Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2535), which risk is most directly associated with "malware"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Malware can steal data, establish persistence, spread, or degrade operations.
  4. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
Practice
2536
Module 7 · Applied Domain 1 · Background malware Unanswered

During a government risk-validation project (GOV-RISK-M07-2536), which risk is most directly associated with "malware"?

View answer choices
  1. Malware can steal data, establish persistence, spread, or degrade operations.
  2. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  3. A control focused on only one objective can leave the other security objectives exposed.
  4. Unmapped detections can leave important adversary techniques without coverage.
Practice
2537
Module 7 · Applied Domain 1 · Background malware Unanswered

During an e-commerce application review (ECOM-WEB-M07-2537), which risk is most directly associated with "malware"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. Malware can steal data, establish persistence, spread, or degrade operations.
Practice
2538
Module 7 · Advanced Domain 1 · Background malware Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2538), which risk is most directly associated with "malware"?

View answer choices
  1. Malware can steal data, establish persistence, spread, or degrade operations.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. A control focused on only one objective can leave the other security objectives exposed.
Practice
2539
Module 7 · Advanced Domain 1 · Background malware Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2539), which risk is most directly associated with "malware"?

View answer choices
  1. Unmapped detections can leave important adversary techniques without coverage.
  2. Malware can steal data, establish persistence, spread, or degrade operations.
  3. A control focused on only one objective can leave the other security objectives exposed.
  4. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
Practice
2540
Module 7 · Advanced Domain 1 · Background malware Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2540), which risk is most directly associated with "malware"?

View answer choices
  1. A control focused on only one objective can leave the other security objectives exposed.
  2. Unmapped detections can leave important adversary techniques without coverage.
  3. Defenders who monitor only the final stage miss earlier opportunities to interrupt an intrusion.
  4. Malware can steal data, establish persistence, spread, or degrade operations.
Practice
2541
Module 7 · Foundation Domain 1 · Background malware Unanswered

During an authorized retail-company assessment (RET-LAB-M07-2541), which action most directly controls the risk related to "malware"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map each asset and threat to confidentiality, integrity, and availability requirements.
  3. Use layered prevention, behavior monitoring, isolation, and tested recovery.
  4. Map controls and detections to relevant ATT&CK techniques and validate coverage.
Practice
2542
Module 7 · Foundation Domain 1 · Background malware Unanswered

During a hospital incident-response exercise (HLT-SOC-M07-2542), which action most directly controls the risk related to "malware"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Use layered prevention, behavior monitoring, isolation, and tested recovery.
  3. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
2543
Module 7 · Foundation Domain 1 · Background malware Unanswered

During a university cyber-range engagement (EDU-RANGE-M07-2543), which action most directly controls the risk related to "malware"?

View answer choices
  1. Place preventive and detective controls across multiple stages of the chain.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Use layered prevention, behavior monitoring, isolation, and tested recovery.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice
2544
Module 7 · Applied Domain 1 · Background malware Unanswered

During a financial-services purple-team test (FIN-PT-M07-2544), which action most directly controls the risk related to "malware"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Place preventive and detective controls across multiple stages of the chain.
  3. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  4. Use layered prevention, behavior monitoring, isolation, and tested recovery.
Practice
2545
Module 7 · Applied Domain 1 · Background malware Unanswered

During a cloud startup security audit (CLD-AUDIT-M07-2545), which action most directly controls the risk related to "malware"?

View answer choices
  1. Use layered prevention, behavior monitoring, isolation, and tested recovery.
  2. Place preventive and detective controls across multiple stages of the chain.
  3. Map each asset and threat to confidentiality, integrity, and availability requirements.
  4. Map controls and detections to relevant ATT&CK techniques and validate coverage.
Practice
2546
Module 7 · Applied Domain 1 · Background malware Unanswered

During a government risk-validation project (GOV-RISK-M07-2546), which action most directly controls the risk related to "malware"?

View answer choices
  1. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  2. Use layered prevention, behavior monitoring, isolation, and tested recovery.
  3. Map each asset and threat to confidentiality, integrity, and availability requirements.
  4. Place preventive and detective controls across multiple stages of the chain.
Practice
2547
Module 7 · Applied Domain 1 · Background malware Unanswered

During an e-commerce application review (ECOM-WEB-M07-2547), which action most directly controls the risk related to "malware"?

View answer choices
  1. Use layered prevention, behavior monitoring, isolation, and tested recovery.
  2. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  3. Place preventive and detective controls across multiple stages of the chain.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice
2548
Module 7 · Advanced Domain 1 · Background malware Unanswered

During a manufacturing and OT security review (MFG-OT-M07-2548), which action most directly controls the risk related to "malware"?

View answer choices
  1. Map each asset and threat to confidentiality, integrity, and availability requirements.
  2. Place preventive and detective controls across multiple stages of the chain.
  3. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  4. Use layered prevention, behavior monitoring, isolation, and tested recovery.
Practice
2549
Module 7 · Advanced Domain 1 · Background malware Unanswered

During a mobile-services penetration test (MOB-TEST-M07-2549), which action most directly controls the risk related to "malware"?

View answer choices
  1. Use layered prevention, behavior monitoring, isolation, and tested recovery.
  2. Place preventive and detective controls across multiple stages of the chain.
  3. Map each asset and threat to confidentiality, integrity, and availability requirements.
  4. Map controls and detections to relevant ATT&CK techniques and validate coverage.
Practice
2550
Module 7 · Advanced Domain 1 · Background malware Unanswered

During a global-enterprise mock CEH scenario (ENT-MOCK-M07-2550), which action most directly controls the risk related to "malware"?

View answer choices
  1. Use layered prevention, behavior monitoring, isolation, and tested recovery.
  2. Place preventive and detective controls across multiple stages of the chain.
  3. Map controls and detections to relevant ATT&CK techniques and validate coverage.
  4. Map each asset and threat to confidentiality, integrity, and availability requirements.
Practice