CAS-003 · Question #30
The Chief Information Security Officer (CISO) has asked the security team to determine whether the organization is susceptible to a zero-day exploit utilized in the banking industry and whether…
The correct answer is D. 1. Analyze the current threat intelligence. The CISO's request involves two parts: (1) determine susceptibility and attribution, and (2) apply signatureless controls. The most logical starting point is Option D - analyze the current threat intelligence. Before gathering external IOCs or deploying any controls, you must…
Question
The Chief Information Security Officer (CISO) has asked the security team to determine whether the organization is susceptible to a zero-day exploit utilized in the banking industry and whether attribution is possible. The CISO has asked what process would be utilized to gather the information, and then wants to apply signatureless controls to stop these kinds of attacks in the future. Which of the following are the MOST appropriate ordered steps to take to meet the CISO's request?
Options
- A
- Perform the ongoing research of the best practices
- B
- Apply artificial intelligence algorithms for detection
- C
- Obtain the latest IOCs from the open source repositories
- D
- Analyze the current threat intelligence
How the community answered
(38 responses)- A13% (5)
- B5% (2)
- C26% (10)
- D55% (21)
Explanation
The CISO's request involves two parts: (1) determine susceptibility and attribution, and (2) apply signatureless controls. The most logical starting point is Option D - analyze the current threat intelligence. Before gathering external IOCs or deploying any controls, you must first understand what intelligence already exists about the threat. This informs which IOCs are relevant and what behavioral patterns to look for. From there, you would obtain and apply IOCs, assess your environment against them, and finally deploy signatureless/behavioral detection (such as AI/ML-based tools) to prevent future occurrences. Option A (ongoing research) is too vague as a first step. Option B (applying AI algorithms) is an implementation step that comes after threat analysis. Option C (obtaining IOCs from open-source repos) is important but should follow an initial threat intelligence review to ensure relevance.
Topics
Community Discussion
No community discussion yet for this question.