nerdexam
CompTIA

CAS-002 · Question #771

A small company's Chief Executive Officer (CEO) has asked its Chief Security Officer (CSO) to improve the company's security posture quickly with regard to targeted attacks. Which of the following…

The correct answer is A. Survey threat feeds from services inside the same industry. Before implementing controls, the CSO should first survey threat intelligence feeds from within the same industry to understand which specific tactics, techniques, and procedures (TTPs) are being used against comparable organizations.

Research and Analysis

Question

A small company's Chief Executive Officer (CEO) has asked its Chief Security Officer (CSO) to improve the company's security posture quickly with regard to targeted attacks. Which of the following should the CSO conduct FIRST?

Options

  • ASurvey threat feeds from services inside the same industry.
  • BPurchase multiple threat feeds to ensure diversity and implement blocks for malicious traffic.
  • CConduct an internal audit against industry best practices to perform a qualitative analysis.
  • DDeploy a UTM solution that receives frequent updates from a trusted industry vendor.

How the community answered

(18 responses)
  • A
    78% (14)
  • B
    6% (1)
  • C
    6% (1)
  • D
    11% (2)

Why each option

Before implementing controls, the CSO should first survey threat intelligence feeds from within the same industry to understand which specific tactics, techniques, and procedures (TTPs) are being used against comparable organizations.

ASurvey threat feeds from services inside the same industry.Correct

Targeted attacks are sector-specific - adversaries often reuse the same infrastructure, malware, and attack vectors against multiple organizations in the same industry. Surveying industry-specific threat feeds (such as an ISAC) gives the CSO immediately actionable intelligence about active campaigns, IOCs, and TTPs relevant to the company before any spending or deployment decisions are made. This ensures that subsequent controls are prioritized against real, current threats rather than generic ones.

BPurchase multiple threat feeds to ensure diversity and implement blocks for malicious traffic.

Purchasing multiple threat feeds and blocking malicious traffic is a reactive implementation step that should follow a threat assessment, not precede it - without context, the CSO risks prioritizing the wrong threats.

CConduct an internal audit against industry best practices to perform a qualitative analysis.

An internal audit against best practices measures the organization's compliance posture qualitatively but does not provide specific intelligence about the targeted adversary or their current TTPs.

DDeploy a UTM solution that receives frequent updates from a trusted industry vendor.

Deploying a UTM solution is a technical control that addresses broad threats but is not targeted to the specific adversary behavior identified in the CERT alert and should follow threat-informed prioritization.

Concept tested: Threat intelligence gathering before security control implementation

Source: https://csrc.nist.gov/publications/detail/sp/800-150/final

Topics

#threat intelligence#threat feeds#targeted attacks#security posture

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice