CAS-003 · Question #935
Historical information shows that a small aerospace R&D company has a lack of user security awareness and is susceptible to nation-state social-engineering attacks and zero-day exploits. A network…
The correct answer is B. Develop a threat model. Before investing in any security control-including the firewall suggested by the network engineer-the CISO must first develop a threat model (B). Threat modeling systematically identifies the organization's assets, potential adversaries (in this case, nation-state actors)…
Question
Historical information shows that a small aerospace R&D company has a lack of user security awareness and is susceptible to nation-state social-engineering attacks and zero-day exploits. A network engineer advises the Chief Information Security Officer (CISO) to invest in a next- generation firewall to guard against incoming traffic and allow for the development of ACLs for new sessions. Which of the following is the FIRST course of action for the CISO to take?
Options
- AConduct a vulnerability scan
- BDevelop a threat model
- CPurchase the firewall as suggested
- DPlace the public-facing website in the DMZ
How the community answered
(53 responses)- A6% (3)
- B83% (44)
- C2% (1)
- D9% (5)
Explanation
Before investing in any security control-including the firewall suggested by the network engineer-the CISO must first develop a threat model (B). Threat modeling systematically identifies the organization's assets, potential adversaries (in this case, nation-state actors), attack vectors (social engineering, zero-days), and the likelihood and impact of each threat. This strategic step ensures that subsequent security investments are risk-informed and properly prioritized rather than reactive. Purchasing a firewall first (C) may be the right decision, but that determination should follow threat modeling. A vulnerability scan (A) is a tactical tool that supports threat modeling but is not the first strategic action. Placing the website in a DMZ (D) is a specific technical control that should be evaluated after the threat model reveals which assets face the highest risk.
Topics
Community Discussion
No community discussion yet for this question.