nerdexam
CompTIA

CAS-003 · Question #25

The Chief Information Security Officer (CISO) for an organization wants to develop custom IDS rulesets faster, prior to new rules being released by IDS vendors. Which of the following BEST meets…

The correct answer is B. Encourage cybersecurity analysts to review open-source intelligence products and threat. The goal is to develop custom IDS rules proactively, ahead of official vendor releases. Option B is correct because open-source intelligence (OSINT) and threat intelligence products are continuously updated by the security community in near-real-time as new threats emerge…

Enterprise Security Operations

Question

The Chief Information Security Officer (CISO) for an organization wants to develop custom IDS rulesets faster, prior to new rules being released by IDS vendors. Which of the following BEST meets this objective?

Options

  • AIdentify a third-party source for IDS rules and change the configuration on the applicable IDSs to
  • BEncourage cybersecurity analysts to review open-source intelligence products and threat
  • CLeverage the latest TCP- and UDP-related RFCs to arm sensors and IDSs with appropriate
  • DUse annual hacking conventions to document the latest attacks and threats, and then develop

How the community answered

(44 responses)
  • A
    2% (1)
  • B
    75% (33)
  • C
    7% (3)
  • D
    16% (7)

Explanation

The goal is to develop custom IDS rules proactively, ahead of official vendor releases. Option B is correct because open-source intelligence (OSINT) and threat intelligence products are continuously updated by the security community in near-real-time as new threats emerge. Cybersecurity analysts who actively monitor these sources can identify new attack techniques, malware behaviors, and exploitation patterns early enough to craft custom detection signatures before vendors formally release them. Option A merely outsources the same problem to another third party and doesn't make rule development faster. Option C references TCP/UDP RFCs, which define protocol standards - not attack signatures - and would not help identify novel threats. Option D (annual hacking conventions) are periodic events and cannot provide the continuous, timely intelligence needed for proactive rule development.

Topics

#IDS rules#threat intelligence#open-source intelligence#custom signatures

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice