nerdexam
CompTIA

CAS-003 · Question #624

An attacker has been compromising banking institution targets across a regional area. The Chief Information Security Officer (CISO) at a local bank wants to detect and prevent an attack before the…

The correct answer is C. Instruct a security engineer to configure the IDS to consume threat intelligence feeds from an. Because an attacker is actively targeting regional banking institutions, threat intelligence feeds - especially from financial sector information-sharing organizations like FS-ISAC - will contain current, campaign-specific IOCs (malicious IPs, domains, file hashes, TTPs)…

Enterprise Security Operations

Question

An attacker has been compromising banking institution targets across a regional area. The Chief Information Security Officer (CISO) at a local bank wants to detect and prevent an attack before the bank becomes a victim. Which of the following actions should the CISO take?

Options

  • AUtilize cloud-based threat analytics to identify anomalous behavior in the company's B2B and
  • BPurchase a CASB solution to identify and control access to cloud-based applications and services
  • CInstruct a security engineer to configure the IDS to consume threat intelligence feeds from an
  • DAttend and present at the regional banking association lobbying group meetings each month and

How the community answered

(42 responses)
  • A
    7% (3)
  • B
    17% (7)
  • C
    74% (31)
  • D
    2% (1)

Explanation

Because an attacker is actively targeting regional banking institutions, threat intelligence feeds - especially from financial sector information-sharing organizations like FS-ISAC - will contain current, campaign-specific IOCs (malicious IPs, domains, file hashes, TTPs) extracted from the ongoing attacks. Configuring the IDS to consume these feeds (C) gives the bank's defenses immediate awareness of the attacker's known infrastructure, enabling detection and blocking before the bank itself is directly targeted. This is proactive, low-cost, and directly relevant to the specific threat. Option A (cloud-based behavioral analytics) is valuable but addresses anomalies, not known-campaign IOCs. Option B (CASB) focuses on cloud app access control. Option D (lobbying meetings) has no operational security impact.

Topics

#threat intelligence#IDS#proactive defense#sector sharing

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice