nerdexam
CompTIA

CAS-001 · Question #479

A small company's Chief Executive Officer (CEO) has asked its Chief Security Officer (CSO) to improve the company's security posture with regard to targeted attacks. Which of the following should…

The correct answer is A. Survey threat feeds from analysts inside the same industry. To improve defenses against targeted attacks, the CSO must first gather threat intelligence specific to the company's industry before selecting or deploying any controls.

Research and Analysis

Question

A small company's Chief Executive Officer (CEO) has asked its Chief Security Officer (CSO) to improve the company's security posture with regard to targeted attacks. Which of the following should the CSO conduct FIRST?

Options

  • ASurvey threat feeds from analysts inside the same industry.
  • BPurchase multiple threat feeds to ensure diversity and implement blocks for malicious traffic.
  • CConduct an internal audit against industry best practices to perform a gap analysis.
  • DDeploy a UTM solution that receives frequent updates from a trusted industry vendor.

How the community answered

(39 responses)
  • A
    74% (29)
  • B
    5% (2)
  • C
    8% (3)
  • D
    13% (5)

Why each option

To improve defenses against targeted attacks, the CSO must first gather threat intelligence specific to the company's industry before selecting or deploying any controls.

ASurvey threat feeds from analysts inside the same industry.Correct

Industry-specific threat feeds from peer analysts provide the most contextually relevant intelligence about adversaries actively targeting that sector, allowing the CSO to understand the actual threat landscape before selecting countermeasures. This intelligence-first approach ensures subsequent controls are calibrated to real, relevant threats rather than generic ones. Surveying industry peers also leverages shared knowledge about attack patterns and tactics specific to that vertical.

BPurchase multiple threat feeds to ensure diversity and implement blocks for malicious traffic.

Purchasing multiple threat feeds and blocking malicious traffic is a reactive, tactical measure that should follow - not precede - understanding which specific threats are relevant to the organization's industry.

CConduct an internal audit against industry best practices to perform a gap analysis.

An internal audit and gap analysis assesses general security maturity against best practices but does not address the specific threat actors or techniques used in targeted attacks against the company's industry.

DDeploy a UTM solution that receives frequent updates from a trusted industry vendor.

Deploying a UTM solution is a technical control implementation step that is only effective after the CSO understands what specific threats need to be mitigated, making it premature before threat intelligence is gathered.

Concept tested: Threat intelligence gathering for targeted attack defense

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-150.pdf

Topics

#threat intelligence#industry threat feeds#security posture#targeted attacks

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice