CAS-003 · Question #453
A systems administrator receives an advisory email that a recently discovered exploit is being used in another country and the financial institutions have ceased operations while they find a way to…
The correct answer is B. Hacker forums E. CVE database. Hacker forums provide early real-world exploit intelligence before formal advisories are published, while the CVE database offers official technical vulnerability details needed to assess system exposure.
Question
A systems administrator receives an advisory email that a recently discovered exploit is being used in another country and the financial institutions have ceased operations while they find a way to respond to the attack. Which of the following BEST describes where the administrator should look to find information on the attack to determine if a response must be prepared for the systems? (Choose two.)
Options
- ABug bounty websites
- BHacker forums
- CAntivirus vendor websites
- DTrade industry association websites
- ECVE database
- FCompany's legal department
How the community answered
(30 responses)- B90% (27)
- C3% (1)
- F7% (2)
Why each option
Hacker forums provide early real-world exploit intelligence before formal advisories are published, while the CVE database offers official technical vulnerability details needed to assess system exposure.
Bug bounty platforms focus on responsibly disclosed vulnerabilities submitted by researchers and are unlikely to contain details about active, weaponized exploits targeting financial institutions.
Hacker forums and threat actor communities frequently discuss active exploits, attack techniques, and indicators of compromise before vendors release patches or formal advisories, making them a valuable early-warning source for understanding how a novel attack works in the wild.
Antivirus vendor websites provide signature updates and threat reports but may not have specific technical analysis of a brand-new zero-day exploit being actively used before detection signatures are developed.
Trade industry associations publish general guidance and standards but are not primary sources for real-time technical exploit intelligence or vulnerability details.
The CVE database provides standardized vulnerability identifiers and technical descriptions that allow administrators to match a reported exploit to specific affected software versions, directly supporting the decision of whether a preparatory response is required for their systems.
The company's legal department handles compliance and liability matters and does not provide technical threat intelligence about vulnerabilities, attack vectors, or exploit details.
Concept tested: Threat intelligence sources for active exploit research
Source: https://www.cve.org/About/Overview
Topics
Community Discussion
No community discussion yet for this question.