CAS-002 · Question #764
A security engineer is responsible for monitoring company applications for known vulnerabilities. Which of the following is a way to stay current on exploits and information security news?
The correct answer is B. Subscribe to security mailing lists. Subscribing to security mailing lists is the most direct and proactive method for a security engineer to receive timely information about new exploits, vulnerability disclosures, and threat intelligence.
Question
A security engineer is responsible for monitoring company applications for known vulnerabilities. Which of the following is a way to stay current on exploits and information security news?
Options
- AUpdate company policies and procedures
- BSubscribe to security mailing lists
- CImplement security awareness training
- DEnsure that the organization vulnerability management plan is up-to-date
How the community answered
(53 responses)- A2% (1)
- B92% (49)
- C2% (1)
- D4% (2)
Why each option
Subscribing to security mailing lists is the most direct and proactive method for a security engineer to receive timely information about new exploits, vulnerability disclosures, and threat intelligence.
Updating internal policies and procedures does not provide any external threat intelligence about new exploits or emerging attack techniques.
Security mailing lists such as those from CISA, SANS Internet Storm Center, vendor security advisories, and CVE announcement lists deliver real-time notifications of newly discovered vulnerabilities and active exploits directly to the engineer. This keeps the engineer informed of threats as they emerge, enabling rapid response before patches or compensating controls are deployed. No other option listed provides this kind of continuous, up-to-date external threat feed.
Security awareness training educates end users about general threats but does not provide the engineer with timely, technical exploit information.
Keeping the vulnerability management plan current is a process improvement activity that does not directly supply current exploit or threat news.
Concept tested: Staying current on vulnerabilities via security mailing lists
Source: https://www.cisa.gov/mailing-lists-and-feeds
Topics
Community Discussion
No community discussion yet for this question.