QuestionQ24
Security OperationsA Chief Information Security Officer (CISO) reviews a threat heat map and observes a significant rise in custom scanning and enumeration activity. The CISO wants to collect as much information as possible about these activities targeting the company in order to help prioritize mitigations. Which of the following solutions would best accomplish this goal?
- A Configuring a honeypot in a separate environment to gather attacker techniques
- B Leveraging canary tokens on all production systems to detect valid intrusion attempts
- C Subscribing to information-sharing and threat intelligence reports for the industry
- D Implementing a web application firewall in front of all applications and having it log attacks
Community Discussion