CompTIA CASP+ (CAS-003) — Question 220

The Chief Information Security Officer (CISO) has asked the security team to determine whether the organization is susceptible to a zero-day exploit utilized in the banking industry and whether attribution is possible. The CISO has asked what process would be utilized to gather the information, and then wants to apply signatureless controls to stop these kinds of attacks in the future. Which of the following are the MOST appropriate ordered steps to take to meet the CISO's request?

Answer options

Correct answer: C

Explanation

Option C is correct because it outlines a systematic approach to gather indicators of compromise (IOCs), assess the network for threats, and prepare for future threats by involving the CERT team. The other options do not follow a clear and effective methodology for identifying and addressing zero-day exploits, often lacking necessary steps or focusing on less relevant techniques.