nerdexam
CompTIA

CAS-003 · Question #841

A Chief Information Security Officer (CISO) wants to obtain data from other organizations in the same industry related to recent attacks against industry targets. A partner firm in the industry…

The correct answer is B. a risk analysis. Collecting threat intelligence from industry partners and evaluating its applicability to the organization's own environment is a risk analysis activity, not simply consuming a feed or building an application model.

Risk Management

Question

A Chief Information Security Officer (CISO) wants to obtain data from other organizations in the same industry related to recent attacks against industry targets. A partner firm in the industry provides information that discloses the attack vector and the affected vulnerability that impacted other firms. The CISO then works with that firm’s CERT to evaluate the organization for applicability associated with the intelligence provided. This activity is an example of:

Options

  • Aan emerging threat feed
  • Ba risk analysis
  • Ca zero-day vulnerability
  • Dthreat modeling
  • Emachine learning
  • FBig Data

How the community answered

(37 responses)
  • A
    8% (3)
  • B
    73% (27)
  • C
    3% (1)
  • D
    3% (1)
  • E
    14% (5)

Why each option

Collecting threat intelligence from industry partners and evaluating its applicability to the organization's own environment is a risk analysis activity, not simply consuming a feed or building an application model.

Aan emerging threat feed

An emerging threat feed is a data source that delivers raw threat information; this scenario describes the analytical activity performed after receiving that information, not the feed itself.

Ba risk analysisCorrect

Risk analysis involves identifying applicable threats, evaluating the vulnerabilities they exploit, and determining the potential impact to the organization. By obtaining intelligence about specific attack vectors and affected vulnerabilities from a partner CERT and then assessing whether those same conditions exist internally, the CISO is performing a structured risk analysis that will inform control decisions based on real threat data.

Ca zero-day vulnerability

A zero-day vulnerability is an unpatched flaw with no public fix; the scenario explicitly describes a disclosed vulnerability shared between known partner organizations.

Dthreat modeling

Threat modeling is a structured engineering process for identifying threats to a specific system's design, not the evaluation of external intelligence for organizational risk applicability.

Emachine learning

Machine learning is a technology used to automate pattern recognition and is not a description of this human-led collaborative threat evaluation activity.

FBig Data

Big Data refers to technologies and methods for processing high-volume datasets, not to manual evaluation of shared intelligence between partner firms.

Concept tested: Threat intelligence sharing and organizational risk analysis

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-30r1.pdf

Topics

#threat intelligence#risk analysis#information sharing#CERT

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice