100-160 Question 187
Select 3You are a cybersecurity technician tasked with identifying potential vulnerabilities in your organization's network using threat intelligence techniques. During your analysis, you come across a report detailing recent attack trends targeting specific open ports and outdated software versions. What should be your next steps to effectively use this threat intelligence?
- A
Review the network's current open ports and compare them against the report's findings.
- B
Update the organization's firewall rules to block all incoming traffic.
- C
Perform a vulnerability scan to identify outdated software versions within the network.
- D
Immediately disable all network services to prevent potential attacks.
- E
Cross-reference the reported attack trends with the organization's existing threat detection logs.
Show answer and explanation
Correct answers: A, C, E
Explanation
To effectively use threat intelligence techniques, you need to map the intelligence (e.g., open ports, outdated software) to your network's current state. Reviewing open ports, scanning for outdated software, and checking threat logs are proactive and targeted actions that address potential vulnerabilities based on the intelligence provided. Broad or disruptive actions, such as blocking all traffic or disabling services, are not aligned with controlled and effective threat mitigation.
- A. Correct.
Reviewing the network's open ports and comparing them against the report's findings is a critical step in identifying specific vulnerabilities that match reported attack trends.
- B. Incorrect.
Blocking all incoming traffic would disrupt legitimate business operations and is not a practical approach to addressing vulnerabilities.
- C. Correct.
Performing a vulnerability scan helps identify outdated software versions, which aligns with the threat intelligence report's focus on such vulnerabilities.
- D. Incorrect.
Disabling all network services would create significant operational downtime and is not a targeted response to the identified threats.
- E. Correct.
Cross-referencing attack trends with threat detection logs allows you to confirm whether the organization has already been targeted by similar attacks or is at risk.