CAS-001 · Question #479
A small company's Chief Executive Officer (CEO) has asked its Chief Security Officer (CSO) to improve the company's security posture with regard to targeted attacks. Which of the following should…
The correct answer is A. Survey threat feeds from analysts inside the same industry. To improve defenses against targeted attacks, the CSO must first gather threat intelligence specific to the company's industry before selecting or deploying any controls.
Question
A small company's Chief Executive Officer (CEO) has asked its Chief Security Officer (CSO) to improve the company's security posture with regard to targeted attacks. Which of the following should the CSO conduct FIRST?
Options
- ASurvey threat feeds from analysts inside the same industry.
- BPurchase multiple threat feeds to ensure diversity and implement blocks for malicious traffic.
- CConduct an internal audit against industry best practices to perform a gap analysis.
- DDeploy a UTM solution that receives frequent updates from a trusted industry vendor.
How the community answered
(39 responses)- A74% (29)
- B5% (2)
- C8% (3)
- D13% (5)
Why each option
To improve defenses against targeted attacks, the CSO must first gather threat intelligence specific to the company's industry before selecting or deploying any controls.
Industry-specific threat feeds from peer analysts provide the most contextually relevant intelligence about adversaries actively targeting that sector, allowing the CSO to understand the actual threat landscape before selecting countermeasures. This intelligence-first approach ensures subsequent controls are calibrated to real, relevant threats rather than generic ones. Surveying industry peers also leverages shared knowledge about attack patterns and tactics specific to that vertical.
Purchasing multiple threat feeds and blocking malicious traffic is a reactive, tactical measure that should follow - not precede - understanding which specific threats are relevant to the organization's industry.
An internal audit and gap analysis assesses general security maturity against best practices but does not address the specific threat actors or techniques used in targeted attacks against the company's industry.
Deploying a UTM solution is a technical control implementation step that is only effective after the CSO understands what specific threats need to be mitigated, making it premature before threat intelligence is gathered.
Concept tested: Threat intelligence gathering for targeted attack defense
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-150.pdf
Topics
Community Discussion
No community discussion yet for this question.