CAS-003 · Question #252
The board of a financial services company has requested that the senior security analyst acts as a cybersecurity advisor in order to comply with recent federal legislation. The analyst is required…
The correct answer is A. Review the CVE database for critical exploits over the past year D. Request information from security vendors and government agencies. Reviewing the CVE (Common Vulnerabilities and Exposures) database (A) provides authoritative, structured data on critical exploits over the past year - directly relevant to threat trends. Requesting information from security vendors and government agencies (D) yields…
Question
The board of a financial services company has requested that the senior security analyst acts as a cybersecurity advisor in order to comply with recent federal legislation. The analyst is required to give a report on current cybersecurity and threat trends in the financial services industry at the next board meeting. Which of the following would be the BEST methods to prepare this report? (Choose two.)
Options
- AReview the CVE database for critical exploits over the past year
- BUse social media to contact industry analysts
- CUse intelligence gathered from the Internet relay chat channels
- DRequest information from security vendors and government agencies
- EPerform a penetration test of the competitor's network and share the results with the board
How the community answered
(53 responses)- A74% (39)
- B4% (2)
- C15% (8)
- E8% (4)
Explanation
Reviewing the CVE (Common Vulnerabilities and Exposures) database (A) provides authoritative, structured data on critical exploits over the past year - directly relevant to threat trends. Requesting information from security vendors and government agencies (D) yields industry-specific, vetted threat intelligence from authoritative sources such as FS-ISAC, CISA, and major security firms. Social media (B) and IRC channels (C) are informal, unverified, and not appropriate for board-level reporting. Penetration testing a competitor's network (E) is illegal without written authorization and would expose the company to serious legal liability.
Topics
Community Discussion
No community discussion yet for this question.