nerdexam
CompTIA

CAS-003 · Question #14

An organization has employed the services of an auditing firm to perform a gap assessment in preparation for an upcoming audit. As part of the gap assessment, the auditor supporting the assessment…

The correct answer is F. Exploit frameworks. Industry partner sharing programs allow organizations to exchange specific technical details about active attacks, including the exploit tools and frameworks used by threat actors targeting their sector.

Research, Development and Collaboration

Question

An organization has employed the services of an auditing firm to perform a gap assessment in preparation for an upcoming audit. As part of the gap assessment, the auditor supporting the assessment recommends the organization engage with other industry partners to share information about emerging attacks to organizations in the industry in which the organization functions. Which of the following types of information could be drawn from such participation?

Options

  • AThreat modeling
  • BRisk assessment
  • CVulnerability data
  • DThreat intelligence
  • ERisk metrics
  • FExploit frameworks

How the community answered

(28 responses)
  • B
    4% (1)
  • E
    4% (1)
  • F
    93% (26)

Why each option

Industry partner sharing programs allow organizations to exchange specific technical details about active attacks, including the exploit tools and frameworks used by threat actors targeting their sector.

AThreat modeling

Threat modeling is an internal structured process for identifying potential threats to a specific system or application, not a type of information obtained from external industry partner sharing.

BRisk assessment

Risk assessment is an internal evaluation methodology for identifying and prioritizing organizational risks, not a product of industry information-sharing participation.

CVulnerability data

Vulnerability data refers to catalogued weaknesses in software and systems typically sourced from databases like the NVD, not primarily from industry partner information exchanges.

DThreat intelligence

Threat intelligence is the overarching discipline of collecting, analyzing, and contextualizing threat data, not a discrete type of shareable information produced by industry partner participation.

ERisk metrics

Risk metrics are quantitative internal measures used to track and communicate an organization's risk posture, not outputs derived from industry partner information sharing.

FExploit frameworksCorrect

Exploit frameworks represent the specific attack tools and methodologies (such as Metasploit or Cobalt Strike) that adversaries actively deploy against organizations in a given industry. By participating in industry threat-sharing groups such as ISACs, an organization can learn which exploit frameworks are being weaponized against sector peers. This concrete technical information enables defenders to configure detection rules and controls against those specific tools.

Concept tested: Industry threat information sharing programs and outputs

Source: https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing

Topics

#threat intelligence#information sharing#industry collaboration#exploit frameworks

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice