CompTIA CASP+ (CAS-003) — Question 14
The Chief Information Security Officer (CISO) for an organization wants to develop custom IDS rulesets faster, prior to new rules being released by IDS vendors.
Which of the following BEST meets this objective?
Answer options
- A. Identify a third-party source for IDS rules and change the configuration on the applicable IDSs to pull in the new rulesets
- B. Encourage cybersecurity analysts to review open-source intelligence products and threat database to generate new IDS rules based on those sources
- C. Leverage the latest TCP- and UDP-related RFCs to arm sensors and IDSs with appropriate heuristics for anomaly detection
- D. Use annual hacking conventions to document the latest attacks and threats, and then develop IDS rules to counter those threats
Correct answer: B
Explanation
Option B is the correct answer because it encourages analysts to actively utilize available intelligence and databases to create relevant rules, which is a proactive approach to cybersecurity. The other options, while helpful, either rely on external sources without customization (A), focus on general heuristics (C), or are reactive and may not keep pace with the speed of evolving threats (D).