An EDR alert shows encoded PowerShell execution on a host. A scanner later flags an unrelated app with CVSS 9.8. When prioritizing detection and response actions for the active incident, which source should guide the analyst?
Select an answer to reveal the explanation.
Short Explanation
Think of ATT&CK as your map of what the attacker is actually doing, while CVSS is just a label on a vulnerability. If the EDR alert is about behavior, you prioritize the technique and the detections that catch it. Don't let an alarming CVSS score for an unrelated bug steer the incident.
Full Explanation
In an active incident, detection and response are behavior-centric. ATT&CK describes adversary techniques such as command execution, persistence, and lateral movement, so technique coverage tells the analyst which detections, containment steps, and hunt queries apply now. The EDR alert already shows a behavior, so mapping it to a technique makes response actionable even when no CVE is identified. The CVSS v4 severity score rates vulnerability exploitability and impact, not whether an observed behavior is being detected or contained; a high score on an unrelated application may drive patching but not incident triage. The EPSS probability score estimates likelihood of exploitation in the wild over time, which is useful for vulnerability queueing, not for choosing containment or detection coverage for a current EDR alert. The KEV catalog status identifies known exploited vulnerabilities for remediation prioritization, but it does not map observed adversary behavior to response actions or coverage gaps. Exam caveat: CompTIA often tests whether you match the framework to the work: ATT&CK for behavior, CVSS for vulnerability severity. Operational check: Map the alert to an ATT&CK technique, review detection coverage for that technique, then use CVSS only for the vulnerability remediation queue.