nerdexam
CompTIA

SY0-501 · Question #388

A small company's Chief Executive Officer (CEO) has asked its Chief Security Officer (CSO) to improve the company's security posture quickly with regard to targeted attacks. Which of the following…

The correct answer is A. Survey threat feeds from services inside the same industry. To quickly improve security against targeted attacks, the Chief Security Officer (CSO) should first gather intelligence on relevant threats by surveying industry-specific threat feeds.

Submitted by marco_it· Mar 4, 2026Security operations

Question

A small company's Chief Executive Officer (CEO) has asked its Chief Security Officer (CSO) to improve the company's security posture quickly with regard to targeted attacks. Which of the following should the CSO conduct FIRST?

Options

  • ASurvey threat feeds from services inside the same industry.
  • BPurchase multiple threat feeds to ensure diversity and implement blocks for malicious traffic.
  • CConduct an internal audit against industry best practices to perform a qualitative analysis.
  • DDeploy a UTM solution that receives frequent updates from a trusted industry vendor.

How the community answered

(29 responses)
  • A
    72% (21)
  • B
    10% (3)
  • C
    14% (4)
  • D
    3% (1)

Why each option

To quickly improve security against targeted attacks, the Chief Security Officer (CSO) should first gather intelligence on relevant threats by surveying industry-specific threat feeds.

ASurvey threat feeds from services inside the same industry.Correct

Surveying threat feeds from within the same industry provides immediate, relevant intelligence on the specific types of targeted attacks and indicators of compromise (IoCs) that the company is likely to face. This intelligence is crucial for prioritizing defenses and making informed decisions before implementing solutions or conducting broader audits.

BPurchase multiple threat feeds to ensure diversity and implement blocks for malicious traffic.

Purchasing and implementing threat feeds is a subsequent action, but the initial step should be to survey and identify which feeds are most relevant and provide the best intelligence for targeted attacks specific to the industry.

CConduct an internal audit against industry best practices to perform a qualitative analysis.

Conducting an internal audit against best practices is a comprehensive, qualitative analysis of the overall security posture and internal controls, which is a longer process and not the quickest first step to address specific, targeted external threats.

DDeploy a UTM solution that receives frequent updates from a trusted industry vendor.

Deploying a UTM solution is an implementation step that should ideally follow an understanding of the specific threats to be mitigated, rather than being the immediate first action when intelligence on targeted attacks is needed.

Concept tested: Prioritization of threat intelligence gathering

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-150.pdf

Topics

#threat intelligence#threat feeds#targeted attacks#security strategy

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice