ISTQB Mock App

Common Attack Pattern Enumeration And Classification

Common Attack Pattern Enumeration and Classification (CAPEC) is a publicly available catalog of known attack patterns used to identify and understand cybersecurity threats.

Official definition
ISTQB Official Glossary Definition
A catalog of known cyber security attack patterns used to prevent attacks.

(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)

View the complete ISTQB Glossary

What is Common Attack Pattern Enumeration And Classification?

CAPEC helps security professionals and testers understand how attackers exploit vulnerabilities so they can design effective security tests and defenses.

Knowledge base: Documents common attack techniques.

Security planning: Supports threat modeling and penetration testing.

Testing value: Helps derive realistic attack scenarios.

Real World Example

An online banking login flow is being reviewed after fraud analysts report repeated attempts to discover valid customer accounts.

The concern is not whether ordinary login works; it is how the system behaves when someone intentionally misuses it. Common attack pattern enumeration and classification points testing toward that hostile or risky behavior.

The tester probes rate limits, error messages, audit events, lockout behavior, and monitoring signals to see whether the system gives attackers useful feedback.

The team strengthens the controls because Common attack pattern enumeration and classification helps them test the product from the perspective of misuse, not only normal customer journeys.

Practice Questions

Question 1

Which use of CAPEC adds MOST value?

Question 2

CAPEC differs from CVE primarily because CAPEC…

Test your knowledge with real ISTQB-style questions

You’ve learned Common Attack Pattern Enumeration And Classification. Test your understanding with topic-specific questions in our Mock Exams.

Go to Mock Exams