Which of the following is the BEST way for an information security manager to learn of zero-day vulnerabilities?
The correct answer is B because cybersecurity threat intelligence groups provide the most effective source of information about zero-day vulnerabilities. Zero-day vulnerabilities are newly discovered or previously unknown weaknesses that may not yet have patches, signatures, or standard scanner checks. Threat intelligence sources can provide early warnings, exploit details, indicators of compromise, affected technologies, attacker tactics, and recommended mitigations. Signature-based malware detection tools are limited because they depend on known malicious patterns and may not detect new threats. Penetration testing can identify weaknesses, but it is periodic and limited to the scope of the test. Vulnerability scanning tools are useful for identifying known vulnerabilities, but they may not detect zero-day vulnerabilities until detection logic is available. In CISM risk management, organizations should maintain awareness of emerging threats and adapt controls as the threat environment changes. Therefore, cybersecurity threat intelligence groups are the best source for learning of zero-day vulnerabilities.
Danica
4 days agoJoanne
9 days agoWilda
14 days ago