nerdexam
Cisco

350-201 · Question #106

An analyst wants to upload an infected file containing sensitive information to a hybrid-analysis sandbox. According to the NIST.SP 800-150 guide to cyber threat information sharing, what is the…

The correct answer is B. Remove all personally identifiable information. NIST SP 800-150 requires analysts to remove all PII from threat data before sharing it externally to protect individual privacy during cyber threat information sharing.

Security Policies and Procedures

Question

An analyst wants to upload an infected file containing sensitive information to a hybrid-analysis sandbox. According to the NIST.SP 800-150 guide to cyber threat information sharing, what is the analyst required to do before uploading the file to safeguard privacy?

Options

  • AVerify hash integrity.
  • BRemove all personally identifiable information.
  • CEnsure the online sandbox is GDPR compliant.
  • DLock the file to prevent unauthorized access.

How the community answered

(52 responses)
  • A
    8% (4)
  • B
    87% (45)
  • C
    2% (1)
  • D
    4% (2)

Why each option

NIST SP 800-150 requires analysts to remove all PII from threat data before sharing it externally to protect individual privacy during cyber threat information sharing.

AVerify hash integrity.

Verifying hash integrity is a data integrity verification step, not a privacy protection requirement specified in NIST SP 800-150 prior to sharing threat information.

BRemove all personally identifiable information.Correct

NIST SP 800-150 explicitly mandates that organizations sanitize threat information by stripping all personally identifiable information before sharing it with external parties, including uploading to third-party sandboxes. This prevents unauthorized disclosure of sensitive personal data embedded in malware samples or infected files shared for analysis purposes.

CEnsure the online sandbox is GDPR compliant.

GDPR compliance is a European regulatory framework and is not cited in NIST SP 800-150 as a prerequisite condition for uploading files to an external sandbox.

DLock the file to prevent unauthorized access.

Locking a file restricts local access but does not mitigate the privacy risk introduced by transmitting sensitive content to a third-party external sandbox environment.

Concept tested: NIST SP 800-150 PII removal before threat intelligence sharing

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-150.pdf

Topics

#NIST SP 800-150#threat intelligence sharing#PII removal#sandbox analysis

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice