The threat assessment team has been asked to identify critical threats to the organization. Which of the following is the best strategy to use?

Prepare for the Cyber Threat Intelligence Analyst Test with our engaging quiz. Enhance your knowledge with multiple-choice questions, complete with explanations and hints. Excel in your exam!

Multiple Choice

The threat assessment team has been asked to identify critical threats to the organization. Which of the following is the best strategy to use?

Explanation:
Identify organizational assets and the threats to those assets, then prioritize threats based on the potential impact. This approach centers on understanding what matters most to the organization—the assets themselves—and then linking what could threaten those assets to the consequences if they were compromised. By starting with asset value and then evaluating how severely each threat could affect operations, safety, and compliance, you get a clear picture of which threats deserve the most attention and resources. Why this works well: it ensures the threat assessment is grounded in business reality, not just in ideas or external chatter. It also naturally integrates both the likelihood and the impact of threats, so defenses can be allocated to protect the most critical assets from the most damaging scenarios. Reasoning about the other approaches helps illuminate why this one fits best. Focusing on brainstorming unknown unknowns without anchoring to asset value can lead to gaps and wasted effort because it’s not tied to what would hurt the organization most. Prioritizing assets alone, without tying specific threats and their potential impact to those assets, risks missing how those threats could actually materialize or the severity of outcomes. Relying only on threat intelligence about known attackers emphasizes who might strike, not the actual risk to assets or the real impact if an attack succeeds, and may overlook other threat types or internal factors.

Identify organizational assets and the threats to those assets, then prioritize threats based on the potential impact. This approach centers on understanding what matters most to the organization—the assets themselves—and then linking what could threaten those assets to the consequences if they were compromised. By starting with asset value and then evaluating how severely each threat could affect operations, safety, and compliance, you get a clear picture of which threats deserve the most attention and resources.

Why this works well: it ensures the threat assessment is grounded in business reality, not just in ideas or external chatter. It also naturally integrates both the likelihood and the impact of threats, so defenses can be allocated to protect the most critical assets from the most damaging scenarios.

Reasoning about the other approaches helps illuminate why this one fits best. Focusing on brainstorming unknown unknowns without anchoring to asset value can lead to gaps and wasted effort because it’s not tied to what would hurt the organization most. Prioritizing assets alone, without tying specific threats and their potential impact to those assets, risks missing how those threats could actually materialize or the severity of outcomes. Relying only on threat intelligence about known attackers emphasizes who might strike, not the actual risk to assets or the real impact if an attack succeeds, and may overlook other threat types or internal factors.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy