nerdexam
CompTIA

CAS-005 · Question #414

An external threat actor attacks public infrastructure providers. In response to the attack and during follow-up activities, various providers share information obtained during response efforts…

The correct answer is D. Failure to integrate with the TIP. Company 2, which has SIEM, UEBA, DLP, and ISAC membership-still shows the slowest detection (20 min) and response (40 min) times. Its only gap is lack of integration with a Threat Intelligence Platform (TIP). Automating the intake, normalization, and enrichment of shared…

Submitted by naveen.iyer· Mar 6, 2026Security Operations

Question

An external threat actor attacks public infrastructure providers. In response to the attack and during follow-up activities, various providers share information obtained during response efforts. After the attack, energy sector companies share their status and response data:

Which of the following is the most important issue to address to defend against future attacks?

Exhibits

CAS-005 question #414 exhibit 1
CAS-005 question #414 exhibit 2

Options

  • AFailure to implement a UEBA system
  • BFailure to implement a DLP system
  • CFailure to join the industry ISAC
  • DFailure to integrate with the TIP

How the community answered

(51 responses)
  • A
    2% (1)
  • B
    6% (3)
  • C
    14% (7)
  • D
    78% (40)

Explanation

Company 2, which has SIEM, UEBA, DLP, and ISAC membership-still shows the slowest detection (20 min) and response (40 min) times. Its only gap is lack of integration with a Threat Intelligence Platform (TIP). Automating the intake, normalization, and enrichment of shared indicators via a TIP lets the SIEM/UEBA/DLP correlate new threat data in real time, cutting both mean time to detect and mean time to respond.

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice