FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
A bank's threat-intelligence function receives 400 indicator feeds from forums, vendors and peers. Analysts spend most time triaging low-value alerts, and several relevant indicators were missed last quarter. Which response best improves the effectiveness of the bank's information-sharing programme?
The bank should prioritise and filter intelligence by relevance to its own technology and threat profile, integrate it into detection and response, and use feedback on usefulness. Adding feeds worsens overload, abandoning external intelligence loses peer learning, and a lone junior analyst is inadequate.
- ASubscribe to additional feeds to increase coverage
- BStop consuming external intelligence and rely on internal logs only
- CPrioritise and filter intelligence by relevance to the bank's own technology and threat profile, and integrate it into detection and response processes with feedback on usefulnessCorrect
- DAssign all feed review to a single junior analyst to reduce cost
Explanation
The problem is volume without relevance, not coverage. Contextual prioritisation, integration into operations and a feedback loop turn intelligence into action. More feeds worsen overload, and dropping external data forfeits learning.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- A bank's cyber-resilience framework sets a recovery time objective (RTO) of 2 hours for its payments platform. After a simulated ransomware …
- A bank applies a defence-in-depth approach to protect a customer database. Which combination best illustrates multiple, independent layers o…
- A bank's cyber strategy is assessed by a supervisor. Which finding most clearly indicates that the strategy is not aligned with sound practi…
- A regulator asks a bank how its cyber-resilience approach keeps pace with changing threats. Which practice would provide the strongest evide…
- A bank's cyber-resilience framework sets a recovery time objective (RTO) of two hours for its payments system. Which statement best describe…
- A bank's cyber-resilience framework sets a recovery time objective (RTO) for its payment-processing system. Which statement best describes w…