350-201 · Question #106
An analyst wants to upload an infected file containing sensitive information to a hybrid-analysis sandbox. According to the NIST.SP 800-150 guide to cyber threat information sharing, what is the…
The correct answer is B. Remove all personally identifiable information. NIST SP 800-150 requires analysts to remove all PII from threat data before sharing it externally to protect individual privacy during cyber threat information sharing.
Question
An analyst wants to upload an infected file containing sensitive information to a hybrid-analysis sandbox. According to the NIST.SP 800-150 guide to cyber threat information sharing, what is the analyst required to do before uploading the file to safeguard privacy?
Options
- AVerify hash integrity.
- BRemove all personally identifiable information.
- CEnsure the online sandbox is GDPR compliant.
- DLock the file to prevent unauthorized access.
How the community answered
(52 responses)- A8% (4)
- B87% (45)
- C2% (1)
- D4% (2)
Why each option
NIST SP 800-150 requires analysts to remove all PII from threat data before sharing it externally to protect individual privacy during cyber threat information sharing.
Verifying hash integrity is a data integrity verification step, not a privacy protection requirement specified in NIST SP 800-150 prior to sharing threat information.
NIST SP 800-150 explicitly mandates that organizations sanitize threat information by stripping all personally identifiable information before sharing it with external parties, including uploading to third-party sandboxes. This prevents unauthorized disclosure of sensitive personal data embedded in malware samples or infected files shared for analysis purposes.
GDPR compliance is a European regulatory framework and is not cited in NIST SP 800-150 as a prerequisite condition for uploading files to an external sandbox.
Locking a file restricts local access but does not mitigate the privacy risk introduced by transmitting sensitive content to a third-party external sandbox environment.
Concept tested: NIST SP 800-150 PII removal before threat intelligence sharing
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-150.pdf
Topics
Community Discussion
No community discussion yet for this question.