CAS-002 · Question #348
A small company's Chief Executive Officer (CEO) has asked its Chief Security Officer (CSO) to improve the company's security posture with regard to targeted attacks. Which of the following should…
The correct answer is A. Survey threat feeds from analysts inside the same industry. Before implementing any controls, the CSO should first survey industry-specific threat intelligence feeds to understand which targeted threats are most relevant to the organization.
Question
A small company's Chief Executive Officer (CEO) has asked its Chief Security Officer (CSO) to improve the company's security posture with regard to targeted attacks. Which of the following should the CSO conduct FIRST?
Options
- ASurvey threat feeds from analysts inside the same industry.
- BPurchase multiple threat feeds to ensure diversity and implement blocks for malicious traffic.
- CConduct an internal audit against industry best practices to perform a gap analysis.
- DDeploy a UTM solution that receives frequent updates from a trusted industry vendor.
How the community answered
(50 responses)- A80% (40)
- B2% (1)
- C6% (3)
- D12% (6)
Why each option
Before implementing any controls, the CSO should first survey industry-specific threat intelligence feeds to understand which targeted threats are most relevant to the organization.
Targeted attacks are highly industry-specific, and consulting threat feeds from analysts within the same sector provides direct intelligence on the tactics, techniques, and procedures (TTPs) adversaries are actively using against similar organizations. This threat-informed baseline is the required first step because every subsequent security investment - controls, policies, or technology - should be prioritized based on actual, relevant adversary behavior. Starting here ensures resources are directed at the real threat landscape rather than generic best practices.
Purchasing multiple threat feeds is premature without first identifying which threat intelligence sources are relevant to the company's specific industry and threat profile.
A gap analysis against best practices measures compliance posture but does not identify the specific adversaries or TTPs targeting the organization, which is the starting point for defending against targeted attacks.
Deploying a UTM is a technical control that should be selected and configured after the threat landscape is understood, not before.
Concept tested: Threat intelligence gathering as first step against targeted attacks
Source: https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing
Topics
Community Discussion
No community discussion yet for this question.