CAS-003 · Question #25
The Chief Information Security Officer (CISO) for an organization wants to develop custom IDS rulesets faster, prior to new rules being released by IDS vendors. Which of the following BEST meets…
The correct answer is B. Encourage cybersecurity analysts to review open-source intelligence products and threat. The goal is to develop custom IDS rules proactively, ahead of official vendor releases. Option B is correct because open-source intelligence (OSINT) and threat intelligence products are continuously updated by the security community in near-real-time as new threats emerge…
Question
The Chief Information Security Officer (CISO) for an organization wants to develop custom IDS rulesets faster, prior to new rules being released by IDS vendors. Which of the following BEST meets this objective?
Options
- AIdentify a third-party source for IDS rules and change the configuration on the applicable IDSs to
- BEncourage cybersecurity analysts to review open-source intelligence products and threat
- CLeverage the latest TCP- and UDP-related RFCs to arm sensors and IDSs with appropriate
- DUse annual hacking conventions to document the latest attacks and threats, and then develop
How the community answered
(44 responses)- A2% (1)
- B75% (33)
- C7% (3)
- D16% (7)
Explanation
The goal is to develop custom IDS rules proactively, ahead of official vendor releases. Option B is correct because open-source intelligence (OSINT) and threat intelligence products are continuously updated by the security community in near-real-time as new threats emerge. Cybersecurity analysts who actively monitor these sources can identify new attack techniques, malware behaviors, and exploitation patterns early enough to craft custom detection signatures before vendors formally release them. Option A merely outsources the same problem to another third party and doesn't make rule development faster. Option C references TCP/UDP RFCs, which define protocol standards - not attack signatures - and would not help identify novel threats. Option D (annual hacking conventions) are periodic events and cannot provide the continuous, timely intelligence needed for proactive rule development.
Topics
Community Discussion
No community discussion yet for this question.