nerdexam
CompTIA

CAS-003 · Question #855

A security team wants to keep up with emerging threats more efficiently by automating NIDS signature development and deployment. Which of the following approaches would BEST support this objective?

The correct answer is B. Subscribe to a commercial service provider that publishes IOCs. Subscribing to a commercial IOC feed provides structured, machine-readable threat data that can be automatically ingested and converted into NIDS signatures, best supporting the automation objective.

Enterprise Security Operations

Question

A security team wants to keep up with emerging threats more efficiently by automating NIDS signature development and deployment. Which of the following approaches would BEST support this objective?

Options

  • AUse open-source intelligence sources to gather current information on adversary
  • BSubscribe to a commercial service provider that publishes IOCs.
  • CMonitor cyberthreat newsgroups and translate articles into IDS/IPS rulesets.
  • DConfigure NIDS to operate inline and use a DNS whitelist.

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    85% (17)
  • C
    10% (2)

Why each option

Subscribing to a commercial IOC feed provides structured, machine-readable threat data that can be automatically ingested and converted into NIDS signatures, best supporting the automation objective.

AUse open-source intelligence sources to gather current information on adversary

Gathering information from open-source intelligence sources is primarily a manual research activity that requires human analysis and curation before signatures can be developed, making it unsuitable for automated deployment.

BSubscribe to a commercial service provider that publishes IOCs.Correct

Commercial threat intelligence providers publish IOCs - including malicious IPs, domains, file hashes, and network behavior patterns - in structured formats such as STIX/TAXII that integrate directly with NIDS platforms for automated signature generation and deployment. This approach enables near-real-time signature updates keyed to active adversary activity without requiring manual research or rule translation. Automated ingestion from a vetted commercial feed directly satisfies the requirement for efficient, scalable signature development and deployment.

CMonitor cyberthreat newsgroups and translate articles into IDS/IPS rulesets.

Monitoring cyberthreat newsgroups and manually translating articles into IDS/IPS rulesets is a labor-intensive, human-driven process that directly contradicts the automation requirement.

DConfigure NIDS to operate inline and use a DNS whitelist.

Configuring NIDS to operate inline with a DNS whitelist is a traffic enforcement and filtering technique that does not address the automated creation or continuous update of threat detection signatures.

Concept tested: Automated NIDS signature deployment via commercial IOC feeds

Source: https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/automated-indicator-sharing-ais

Topics

#NIDS signatures#threat intelligence#IOC feeds#automation

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice