CAS-005 · Question #414
An external threat actor attacks public infrastructure providers. In response to the attack and during follow-up activities, various providers share information obtained during response efforts…
The correct answer is D. Failure to integrate with the TIP. Company 2, which has SIEM, UEBA, DLP, and ISAC membership-still shows the slowest detection (20 min) and response (40 min) times. Its only gap is lack of integration with a Threat Intelligence Platform (TIP). Automating the intake, normalization, and enrichment of shared…
Question
An external threat actor attacks public infrastructure providers. In response to the attack and during follow-up activities, various providers share information obtained during response efforts. After the attack, energy sector companies share their status and response data:
Which of the following is the most important issue to address to defend against future attacks?
Exhibits
Options
- AFailure to implement a UEBA system
- BFailure to implement a DLP system
- CFailure to join the industry ISAC
- DFailure to integrate with the TIP
How the community answered
(51 responses)- A2% (1)
- B6% (3)
- C14% (7)
- D78% (40)
Explanation
Company 2, which has SIEM, UEBA, DLP, and ISAC membership-still shows the slowest detection (20 min) and response (40 min) times. Its only gap is lack of integration with a Threat Intelligence Platform (TIP). Automating the intake, normalization, and enrichment of shared indicators via a TIP lets the SIEM/UEBA/DLP correlate new threat data in real time, cutting both mean time to detect and mean time to respond.
Community Discussion
No community discussion yet for this question.

