CAS-003 · Question #14
An organization has employed the services of an auditing firm to perform a gap assessment in preparation for an upcoming audit. As part of the gap assessment, the auditor supporting the assessment…
The correct answer is F. Exploit frameworks. Industry partner sharing programs allow organizations to exchange specific technical details about active attacks, including the exploit tools and frameworks used by threat actors targeting their sector.
Question
An organization has employed the services of an auditing firm to perform a gap assessment in preparation for an upcoming audit. As part of the gap assessment, the auditor supporting the assessment recommends the organization engage with other industry partners to share information about emerging attacks to organizations in the industry in which the organization functions. Which of the following types of information could be drawn from such participation?
Options
- AThreat modeling
- BRisk assessment
- CVulnerability data
- DThreat intelligence
- ERisk metrics
- FExploit frameworks
How the community answered
(28 responses)- B4% (1)
- E4% (1)
- F93% (26)
Why each option
Industry partner sharing programs allow organizations to exchange specific technical details about active attacks, including the exploit tools and frameworks used by threat actors targeting their sector.
Threat modeling is an internal structured process for identifying potential threats to a specific system or application, not a type of information obtained from external industry partner sharing.
Risk assessment is an internal evaluation methodology for identifying and prioritizing organizational risks, not a product of industry information-sharing participation.
Vulnerability data refers to catalogued weaknesses in software and systems typically sourced from databases like the NVD, not primarily from industry partner information exchanges.
Threat intelligence is the overarching discipline of collecting, analyzing, and contextualizing threat data, not a discrete type of shareable information produced by industry partner participation.
Risk metrics are quantitative internal measures used to track and communicate an organization's risk posture, not outputs derived from industry partner information sharing.
Exploit frameworks represent the specific attack tools and methodologies (such as Metasploit or Cobalt Strike) that adversaries actively deploy against organizations in a given industry. By participating in industry threat-sharing groups such as ISACs, an organization can learn which exploit frameworks are being weaponized against sector peers. This concrete technical information enables defenders to configure detection rules and controls against those specific tools.
Concept tested: Industry threat information sharing programs and outputs
Source: https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing
Topics
Community Discussion
No community discussion yet for this question.