Home > Glossary > CompTIA Advanced Security Practitioner+ > Common Attack Pattern Enumeration and Classification (CAPEC)

📖 What is Common Attack Pattern Enumeration and Classification (CAPEC)?

Common Attack Pattern Enumeration and Classification (CAPEC) is a comprehensive dictionary of known patterns of attack used by adversaries. It provides a standardized way to describe attack methods, helping security professionals identify potential weaknesses and develop effective countermeasures.

🥋 Sensei Says:

"Don't confuse CAPEC with CVE. CVE is about the vulnerability (the hole), while CAPEC is about the attack pattern (how the hole is exploited)."

📚 Certification: CompTIA Advanced Security Practitioner+ (CAS-004)

🔑 What are the Key Concepts of Common Attack Pattern Enumeration and Classification (CAPEC)?

  • Focuses on the 'how' of an attack, describing the methodology and patterns used by adversaries regardless of the specific target software.
  • Used extensively in threat modeling to anticipate potential attack vectors and design proactive security controls based on known adversary behaviors.
  • Provides a standardized taxonomy that allows security teams to communicate threat intelligence consistently across different tools and organizational silos.
  • Complements MITRE ATT&CK by providing more granular, pattern-level detail on the specific mechanics of an exploit compared to high-level techniques.
  • Enables the mapping of attack patterns to specific countermeasures, allowing architects to validate that a control effectively mitigates a known pattern.

🎯 How does Common Attack Pattern Enumeration and Classification (CAPEC) appear on the CAS-004 Exam?

You may be asked to identify the best resource for understanding the general methodology an attacker uses to perform a specific attack, such as SQL Injection, across various platforms and software versions.

A scenario might describe a security architect performing threat modeling for a new application and ask which framework provides a comprehensive dictionary of known attack patterns to anticipate adversary behavior.

Expect questions that require you to differentiate between a specific software vulnerability listed as a CVE and the general method used to exploit that vulnerability, which is categorized by CAPEC.

❓ Frequently Asked Questions

How does CAPEC differ from the MITRE ATT&CK framework?

ATT&CK describes the high-level tactics and techniques observed in real-world attacks. CAPEC provides a more granular look at the specific attack patterns and the mechanical steps an adversary takes to achieve an objective.


If I have a CVE ID, why would I also look at CAPEC?

A CVE tells you that a specific hole exists in a specific version of software. CAPEC explains the general method of attack used to exploit that hole, helping you defend against similar patterns elsewhere.

Related Terms from CompTIA Advanced Security Practitioner+

📝 Related Study Guides

Comparison 8 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

Choose CISSP if you want broad technical security expertise across eight domains, including cryptography, network security, and software development. Choose CISM if you're focused on information security management, governance, and risk management from a leadership perspective. CISSP is ideal for hands-on security architects, while CISM is designed for security managers and directors.

Career Guide 9 min read

The IT Certification Roadmap: Where to Start in 2026

Start your IT certification journey in 2026 with CompTIA A+ for general IT foundations, then branch into networking (Network+), cybersecurity (Security+), or cloud computing (AWS Cloud Practitioner or Azure Fundamentals) based on your career goals. Each path leads to advanced certifications like CISSP, AWS Solutions Architect, or CISM within 2-3 years of focused progression.

Comparison 10 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

The CISSP is a broad, technical-to-managerial certification focusing on security operations and architecture across eight domains. In contrast, CISM is a specialized management certification centered on governance, risk management, and program development. Choose CISSP for comprehensive security expertise and CISM if you are pivoting specifically into security leadership and governance roles.

🧠

Test Your Knowledge

Think you understand Common Attack Pattern Enumeration and Classification (CAPEC)? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium