nerdexam
CompTIA

CAS-003 · Question #453

A systems administrator receives an advisory email that a recently discovered exploit is being used in another country and the financial institutions have ceased operations while they find a way to…

The correct answer is B. Hacker forums E. CVE database. Hacker forums provide early real-world exploit intelligence before formal advisories are published, while the CVE database offers official technical vulnerability details needed to assess system exposure.

Research, Development and Collaboration

Question

A systems administrator receives an advisory email that a recently discovered exploit is being used in another country and the financial institutions have ceased operations while they find a way to respond to the attack. Which of the following BEST describes where the administrator should look to find information on the attack to determine if a response must be prepared for the systems? (Choose two.)

Options

  • ABug bounty websites
  • BHacker forums
  • CAntivirus vendor websites
  • DTrade industry association websites
  • ECVE database
  • FCompany's legal department

How the community answered

(30 responses)
  • B
    90% (27)
  • C
    3% (1)
  • F
    7% (2)

Why each option

Hacker forums provide early real-world exploit intelligence before formal advisories are published, while the CVE database offers official technical vulnerability details needed to assess system exposure.

ABug bounty websites

Bug bounty platforms focus on responsibly disclosed vulnerabilities submitted by researchers and are unlikely to contain details about active, weaponized exploits targeting financial institutions.

BHacker forumsCorrect

Hacker forums and threat actor communities frequently discuss active exploits, attack techniques, and indicators of compromise before vendors release patches or formal advisories, making them a valuable early-warning source for understanding how a novel attack works in the wild.

CAntivirus vendor websites

Antivirus vendor websites provide signature updates and threat reports but may not have specific technical analysis of a brand-new zero-day exploit being actively used before detection signatures are developed.

DTrade industry association websites

Trade industry associations publish general guidance and standards but are not primary sources for real-time technical exploit intelligence or vulnerability details.

ECVE databaseCorrect

The CVE database provides standardized vulnerability identifiers and technical descriptions that allow administrators to match a reported exploit to specific affected software versions, directly supporting the decision of whether a preparatory response is required for their systems.

FCompany's legal department

The company's legal department handles compliance and liability matters and does not provide technical threat intelligence about vulnerabilities, attack vectors, or exploit details.

Concept tested: Threat intelligence sources for active exploit research

Source: https://www.cve.org/About/Overview

Topics

#threat intelligence#CVE database#security advisories#exploit research

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice