CAS-002 · Question #319
A security analyst is tasked to create an executive briefing, which explains the activity and motivation of a cyber adversary. Which of the following is the MOST important content for the brief for…
The correct answer is D. Threat actor types, threat actor motivation, and the attack impact. An executive briefing on a cyber adversary must center on threat actor types, motivation, and attack impact because management decisions are driven by business risk, not technical mechanics. Impact directly translates threat activity into organizational consequences that…
Question
A security analyst is tasked to create an executive briefing, which explains the activity and motivation of a cyber adversary. Which of the following is the MOST important content for the brief for management personnel to understand?
Options
- AThreat actor types, threat actor motivation, and attack tools
- BUnsophisticated agents, organized groups, and nation states
- CThreat actor types, attack sophistication, and the anatomy of an attack
- DThreat actor types, threat actor motivation, and the attack impact
How the community answered
(29 responses)- A14% (4)
- B3% (1)
- C10% (3)
- D72% (21)
Why each option
An executive briefing on a cyber adversary must center on threat actor types, motivation, and attack impact because management decisions are driven by business risk, not technical mechanics. Impact directly translates threat activity into organizational consequences that executives can act on.
Attack tools are a technical implementation detail relevant to security engineers and incident responders, not to executives who need business impact information to make strategic decisions.
Listing only actor categories such as unsophisticated agents and nation states, without motivation or impact, gives management insufficient context to assess organizational risk or justify security investment.
Attack sophistication and the anatomy of an attack are operationally focused details intended for security analysts and SOC personnel; executives require impact-oriented content rather than technical attack chain descriptions.
Threat actor types give executives context on who is targeting the organization and their likely capabilities. Threat actor motivation explains why the organization is being targeted, enabling prioritization of assets and controls. Attack impact - the potential financial, operational, and reputational damage - is the most critical element for management because it directly informs risk acceptance decisions and resource allocation.
Concept tested: Executive-level cyber threat intelligence briefing content
Source: https://www.cisa.gov/resources-tools/resources/cyber-threat-intelligence
Topics
Community Discussion
No community discussion yet for this question.