nerdexam
Isaca

CRISC · Question #457

Which of the following is the MOST useful information an organization can obtain from external sources about emerging threats?

The correct answer is C. Indicators for detecting the presence of threatsl). The most useful information an organization can obtain from external sources about emerging threats is indicators for detecting their presence, enabling proactive defense.

Submitted by yousef_jo· Apr 18, 2026IT Risk Assessment

Question

Which of the following is the MOST useful information an organization can obtain from external sources about emerging threats?

Options

  • ASolutions for eradicating emerging threats
  • BCost to mitigate the risk resulting from threats
  • CIndicators for detecting the presence of threatsl)
  • DSource and identity of attackers

How the community answered

(39 responses)
  • A
    3% (1)
  • C
    95% (37)
  • D
    3% (1)

Why each option

The most useful information an organization can obtain from external sources about emerging threats is indicators for detecting their presence, enabling proactive defense.

ASolutions for eradicating emerging threats

While solutions are useful, detecting the threat first is paramount. Solutions are often specific to an organization's environment and may not be universally provided or applicable from external sources.

BCost to mitigate the risk resulting from threats

The cost to mitigate is highly dependent on an organization's specific environment, existing controls, and financial situation, making external, general cost information less directly useful than detection capabilities.

CIndicators for detecting the presence of threatsl)Correct

Indicators of Compromise (IoCs) or other threat indicators, such as signatures, hashes, IP addresses, or Tactics, Techniques, and Procedures (TTPs), derived from external threat intelligence, allow an organization to detect active threats within its environment before significant damage occurs. This enables proactive monitoring and defense.

DSource and identity of attackers

While knowing the source and identity of attackers can be valuable for attribution or law enforcement, it is less immediately useful for preventing or detecting an active attack than knowing how to identify the threat itself within an organization's systems.

Concept tested: Threat intelligence and indicators

Source: https://learn.microsoft.com/en-us/azure/security-center/security-center-threat-intelligence

Topics

#Threat intelligence#Emerging threats#Risk identification#Threat detection

Community Discussion

No community discussion yet for this question.

Full CRISC Practice