312-50V11 · Question #633
Bob is acknowledged as a hacker of repute and is popular among visitors of "underground" sites. Bob is willing to share his knowledge with those who are willing to learn, and many have expressed…
The correct answer is A. Educate everyone with books, articles and training on risk analysis, vulnerabilities and. Bridging the knowledge gap between attackers and defenders is best achieved through broad education on risk analysis and vulnerabilities. This scales across the entire security community rather than targeting narrow groups.
Question
Bob is acknowledged as a hacker of repute and is popular among visitors of "underground" sites. Bob is willing to share his knowledge with those who are willing to learn, and many have expressed their interest in learning from him. However, this knowledge has a risk associated with it, as it can be used for malevolent attacks as well. In this context, what would be the most affective method to bridge the knowledge gap between the "black" hats or crackers and the "white" hats or computer security professionals? (Choose the test answer)
Options
- AEducate everyone with books, articles and training on risk analysis, vulnerabilities and
- BHire more computer security monitoring personnel to monitor computer systems and networks.
- CMake obtaining either a computer security certification or accreditation easier to achieve so more
- DTrain more National Guard and reservist in the art of computer security to help out in times of
How the community answered
(32 responses)- A91% (29)
- B6% (2)
- C3% (1)
Why each option
Bridging the knowledge gap between attackers and defenders is best achieved through broad education on risk analysis and vulnerabilities. This scales across the entire security community rather than targeting narrow groups.
Broad education through books, articles, and training on risk analysis and vulnerabilities equips defenders with the same foundational knowledge attackers possess. This approach is scalable and sustainable, raising the overall security baseline across the entire professional community. It empowers white-hat professionals to understand offensive techniques necessary to build effective defenses.
Hiring more monitoring personnel addresses detection after compromise but does not close the underlying knowledge gap between attackers and defenders.
Lowering the bar to obtain certifications reduces the depth of technical knowledge required and does not ensure professionals can counter skilled attackers.
Training National Guard and reservists addresses a narrow workforce segment and does not broadly close the knowledge gap across the civilian security community.
Concept tested: Security education and knowledge gap mitigation strategy
Source: https://niccs.cisa.gov/education-training
Topics
Community Discussion
No community discussion yet for this question.