312-50V12 · Question #152
Given the complexities of an organization's network infrastructure, a threat actor has exploited an unidentified vulnerability, leading to a major data breach. As a Certified Ethical Hacker (CEH). you
The correct answer is D. Adopt a Continual/Adaptive Security Strategy involving ongoing prediction, prevention, detection,. When an organization faces an unidentified vulnerability leading to a major breach, a dynamic and ongoing security approach is required rather than a static or one-time framework. The Continual/Adaptive Security Strategy best addresses the evolving nature of modern threats.
Question
Options
- ADevelop an in-depth Risk Management process, involving identification, assessment, treatment,
- BEstablish a Defense-in-Depth strategy, incorporating multiple layers of security measures to
- CImplement an Information Assurance (IA) policy focusing on ensuring the integrity, availability,
- DAdopt a Continual/Adaptive Security Strategy involving ongoing prediction, prevention, detection,
How the community answered
(35 responses)- A11% (4)
- B6% (2)
- C23% (8)
- D60% (21)
Why each option
When an organization faces an unidentified vulnerability leading to a major breach, a dynamic and ongoing security approach is required rather than a static or one-time framework. The Continual/Adaptive Security Strategy best addresses the evolving nature of modern threats.
Risk Management is a foundational process for identifying and prioritizing known risks, but it does not inherently provide continuous, real-time defense mechanisms needed to address actively exploited, unidentified vulnerabilities.
Defense-in-Depth adds layered security controls and is a strong tactical approach, but it is a static architectural model that does not incorporate the ongoing prediction, detection, and adaptive response cycles needed to counter evolving unknown threats.
Information Assurance focuses on ensuring data integrity, availability, and confidentiality through policy, but it is primarily a governance and policy framework rather than a dynamic, operationally adaptive security strategy capable of responding to novel attack vectors.
An Adaptive/Continual Security Strategy employs a cyclical model of Predict, Prevent, Detect, and Respond, enabling organizations to continuously evolve defenses against emerging and unknown threats. Since the breach stemmed from an unidentified vulnerability, a static strategy would be insufficient; the adaptive model ensures ongoing threat intelligence, real-time monitoring, and iterative improvement. This approach, aligned with frameworks like Gartner's Adaptive Security Architecture, is the most comprehensive answer to persistent, sophisticated threat actors.
Concept tested: Adaptive/Continual Security Strategy for evolving threat response
Source: https://www.eccouncil.org/cybersecurity-exchange/ethical-hacking/adaptive-security-strategy/
Topics
Community Discussion
No community discussion yet for this question.