SY0-501 · Question #388
A small company's Chief Executive Officer (CEO) has asked its Chief Security Officer (CSO) to improve the company's security posture quickly with regard to targeted attacks. Which of the following…
The correct answer is A. Survey threat feeds from services inside the same industry. To quickly improve security against targeted attacks, the Chief Security Officer (CSO) should first gather intelligence on relevant threats by surveying industry-specific threat feeds.
Question
A small company's Chief Executive Officer (CEO) has asked its Chief Security Officer (CSO) to improve the company's security posture quickly with regard to targeted attacks. Which of the following should the CSO conduct FIRST?
Options
- ASurvey threat feeds from services inside the same industry.
- BPurchase multiple threat feeds to ensure diversity and implement blocks for malicious traffic.
- CConduct an internal audit against industry best practices to perform a qualitative analysis.
- DDeploy a UTM solution that receives frequent updates from a trusted industry vendor.
How the community answered
(29 responses)- A72% (21)
- B10% (3)
- C14% (4)
- D3% (1)
Why each option
To quickly improve security against targeted attacks, the Chief Security Officer (CSO) should first gather intelligence on relevant threats by surveying industry-specific threat feeds.
Surveying threat feeds from within the same industry provides immediate, relevant intelligence on the specific types of targeted attacks and indicators of compromise (IoCs) that the company is likely to face. This intelligence is crucial for prioritizing defenses and making informed decisions before implementing solutions or conducting broader audits.
Purchasing and implementing threat feeds is a subsequent action, but the initial step should be to survey and identify which feeds are most relevant and provide the best intelligence for targeted attacks specific to the industry.
Conducting an internal audit against best practices is a comprehensive, qualitative analysis of the overall security posture and internal controls, which is a longer process and not the quickest first step to address specific, targeted external threats.
Deploying a UTM solution is an implementation step that should ideally follow an understanding of the specific threats to be mitigated, rather than being the immediate first action when intelligence on targeted attacks is needed.
Concept tested: Prioritization of threat intelligence gathering
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-150.pdf
Topics
Community Discussion
No community discussion yet for this question.