CAS-003 · Question #855
A security team wants to keep up with emerging threats more efficiently by automating NIDS signature development and deployment. Which of the following approaches would BEST support this objective?
The correct answer is B. Subscribe to a commercial service provider that publishes IOCs. Subscribing to a commercial IOC feed provides structured, machine-readable threat data that can be automatically ingested and converted into NIDS signatures, best supporting the automation objective.
Question
A security team wants to keep up with emerging threats more efficiently by automating NIDS signature development and deployment. Which of the following approaches would BEST support this objective?
Options
- AUse open-source intelligence sources to gather current information on adversary
- BSubscribe to a commercial service provider that publishes IOCs.
- CMonitor cyberthreat newsgroups and translate articles into IDS/IPS rulesets.
- DConfigure NIDS to operate inline and use a DNS whitelist.
How the community answered
(20 responses)- A5% (1)
- B85% (17)
- C10% (2)
Why each option
Subscribing to a commercial IOC feed provides structured, machine-readable threat data that can be automatically ingested and converted into NIDS signatures, best supporting the automation objective.
Gathering information from open-source intelligence sources is primarily a manual research activity that requires human analysis and curation before signatures can be developed, making it unsuitable for automated deployment.
Commercial threat intelligence providers publish IOCs - including malicious IPs, domains, file hashes, and network behavior patterns - in structured formats such as STIX/TAXII that integrate directly with NIDS platforms for automated signature generation and deployment. This approach enables near-real-time signature updates keyed to active adversary activity without requiring manual research or rule translation. Automated ingestion from a vetted commercial feed directly satisfies the requirement for efficient, scalable signature development and deployment.
Monitoring cyberthreat newsgroups and manually translating articles into IDS/IPS rulesets is a labor-intensive, human-driven process that directly contradicts the automation requirement.
Configuring NIDS to operate inline with a DNS whitelist is a traffic enforcement and filtering technique that does not address the automated creation or continuous update of threat detection signatures.
Concept tested: Automated NIDS signature deployment via commercial IOC feeds
Source: https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/automated-indicator-sharing-ais
Topics
Community Discussion
No community discussion yet for this question.