CAS-003 · Question #871
The Chief Information Security Officer (CISO) developed a robust plan to address both internal and external vulnerabilities due to an increase in ransomware attacks on the network. However, the…
The correct answer is B. The threat model was not vetted properly. When a well-designed security plan still fails to stop attacks, the most likely root cause is a flawed threat model that did not accurately represent the actual threat landscape.
Question
The Chief Information Security Officer (CISO) developed a robust plan to address both internal and external vulnerabilities due to an increase in ransomware attacks on the network. However, the number of successful attacks continues to increase. Which of the following is the MOST likely failure?
Options
- AThe company did not blacklist suspected websites properly.
- BThe threat model was not vetted properly.
- CThe IDS/IPS were not updated with the latest malware signatures.
- DThe organization did not conduct a business impact analysis.
How the community answered
(39 responses)- A5% (2)
- B69% (27)
- C18% (7)
- D8% (3)
Why each option
When a well-designed security plan still fails to stop attacks, the most likely root cause is a flawed threat model that did not accurately represent the actual threat landscape.
Blacklisting suspected websites addresses only one potential delivery channel for ransomware and is a symptom of a broader control gap rather than the root cause of a comprehensive plan's failure.
A threat model defines which adversaries, attack vectors, and scenarios are in scope for a security program. If the threat model was not properly vetted, it may have excluded the specific ransomware delivery methods or threat actors actually targeting the organization, causing the controls derived from it to be misaligned with real-world attacks. No matter how robustly a plan is implemented, it will fail if the underlying threat assumptions are inaccurate.
Outdated IDS/IPS signatures are a contributing operational factor but represent a downstream control failure, not the foundational planning failure that would explain a pattern of increasing successful attacks.
A business impact analysis identifies critical assets and recovery priorities for continuity planning but does not directly inform the design of preventive security controls against ransomware.
Concept tested: Threat modeling accuracy and security plan effectiveness
Source: https://csrc.nist.gov/pubs/sp/800/154/final
Topics
Community Discussion
No community discussion yet for this question.