712-50 Question 352
Single answerThreat Management (5 questions)A global manufacturing company has expanded through acquisition and now operates multiple security monitoring tools across business units. The board has asked the CISO to reduce the organization's exposure to ransomware, but the current threat management program produces large volumes of alerts with inconsistent prioritization. Recent incidents showed that analysts spent significant time investigating low-value events while a credential-theft campaign affecting a critical plant network was identified too late. Given limited budget for the next fiscal year, which action should the CISO prioritize FIRST to improve threat management effectiveness and align detection efforts to business risk?
- A
Implement a threat-led use case and detection engineering program that maps intelligence on ransomware and credential-theft tactics to the organization's crown jewels and critical business processes
- B
Acquire an additional endpoint detection tool for all business units so that every acquired subsidiary uses the same agent and console
- C
Increase the SOC alert escalation threshold so analysts only investigate high-severity alerts generated by existing tools
- D
Outsource all tier-1 alert triage to a managed security service provider to reduce internal workload
Show answer and explanation
Correct answer: A
Explanation
The best answer is to first establish a threat-led, business-aligned detection strategy. At the CCISO level, threat management is not primarily about acquiring more tools or shifting operational burden; it is about ensuring the program is driven by business risk, current threat intelligence, and protection of crown jewels. In this scenario, ransomware and credential theft have already demonstrated business impact, especially in critical plant operations. Therefore, the CISO should prioritize identifying the most relevant threat scenarios, mapping them to critical assets and processes, and then building or tuning use cases, telemetry, triage workflows, and response playbooks accordingly.
This reflects recognized best practices: NIST CSF 2.0 emphasizes governance and risk-based prioritization across detection and response; NIST SP 800-61 Rev. 2 stresses preparation, analysis, and aligning incident handling capabilities to likely threats; MITRE ATT&CK is commonly used to map adversary tactics and improve coverage against real attack techniques. From an executive perspective, this approach also supports budget discipline by improving effectiveness of existing investments before adding new tools or outsourcing services.
- A. Correct.
Correct. This is the strongest first step because it addresses the core problem: threat management is not sufficiently aligned to the organization's most relevant threats and highest-value assets. A threat-led use case and detection engineering program helps the CISO focus limited resources on the techniques, procedures, and attack paths most likely to impact critical operations, such as ransomware propagation and credential theft into plant networks. In practice, this means prioritizing detections around privileged account misuse, lateral movement, remote access abuse, backup tampering, and suspicious access to industrial or operational environments. This approach improves signal quality, supports risk-based prioritization, and is consistent with best practices from NIST Cybersecurity Framework 2.0 (Govern/Protect/Detect functions), NIST SP 800-61 for incident handling preparation, and MITRE ATT&CK-based detection planning.
- B. Incorrect.
Incorrect. Tool consolidation may eventually be valuable, but buying another endpoint tool does not by itself solve poor prioritization, inconsistent use cases, or weak alignment to business risk. Organizations often already have more telemetry than they can effectively operationalize. Without defining threat-informed detection requirements, a new tool can increase alert volume and complexity rather than improve outcomes. Someone might choose this option because standardization sounds efficient, but the scenario indicates the primary issue is ineffective threat management and prioritization, not merely lack of tooling.
- C. Incorrect.
Incorrect. Raising escalation thresholds is a blunt reduction mechanism that may decrease analyst workload but also risks suppressing important early indicators of compromise. Severity labels generated by tools are not a substitute for contextual, business-aligned threat prioritization. In the scenario, the organization already missed a credential-theft campaign affecting a critical plant network; simply filtering more aggressively could worsen that problem. This option reflects the common misconception that alert fatigue is best solved by looking at fewer alerts rather than by engineering better detections and triage logic.
- D. Incorrect.
Incorrect. Outsourcing tier-1 triage can help with staffing constraints, but it should not be the first priority here. An MSSP can only triage effectively based on the organization's logging quality, use cases, escalation criteria, and understanding of critical assets. If those foundations are weak, the provider may process volume without materially improving detection of the threats that matter most. This option is plausible because it addresses workload, but it does not directly correct the strategic misalignment between threats, assets, and monitoring priorities.