hardMultiple Select
CISM Practice Question: Which THREE are valid sources for threat…
Which THREE are valid sources for threat intelligence that can be used during incident response? (Choose three.)
⚠ Common exam trap
ISACA CISM often tests the distinction between operational data (logs) and external threat intelligence, leading candidates to incorrectly select internal logs as a threat intelligence source instead of recognizing them as evidence for detection and analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Industry information sharing groups
Option B (Industry information sharing groups) is correct because organizations such as ISACs (Information Sharing and Analysis Centers) and CERTs distribute vetted threat indicators, TTPs, and advisories that directly inform incident response decisions. Option C (Vendor vulnerability databases) is correct because sources like the NVD, CVE, and vendor security advisories provide authoritative vulnerability details, CVSS scores, and patch guidance used to assess and remediate incidents. Option D (Open-source intelligence, OSINT) is correct because publicly available data such as threat feeds, malware analyses, and attacker infrastructure from security blogs, forums, and repositories enriches incident context and attribution. Option A is not a valid threat intelligence source because employee social media posts are unvetted, potentially unreliable, and not structured intelligence. Option E is not a threat intelligence source but internal telemetry; network traffic logs are evidence collected during incident response, not external intelligence about threats.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Social media posts from employees
Why it's wrong here
Employee social media posts are unstructured, unverified, and lack indicators of compromise or adversary tactics, so they cannot reliably inform incident response. They are tempting as open-source intelligence, but formal OSINT feeds, vendor reports, and ISAC sharing are the valid sources.
- ✓
Industry information sharing groups
Why this is correct
Industry information sharing groups, such as ISACs, supply sector-specific indicators and adversary tactics that internal telemetry alone cannot reveal. This satisfies the stem's requirement for valid threat intelligence sources during incident response, because members exchange anonymised, timely data on active campaigns affecting comparable environments, enriching detection and prioritisation beyond Microsoft Entra ID logs.
- ✓
Vendor vulnerability databases
Why this is correct
Vendor vulnerability databases publish authoritative details on known flaws, patches and exploitability. Consulting them during incident response identifies whether observed activity maps to a documented vulnerability, satisfying the need for a structured, vendor-maintained intelligence source.
- ✓
Open-source intelligence (OSINT)
Why this is correct
Open-source intelligence draws on publicly available data such as forums, paste sites and security blogs to reveal attacker infrastructure and indicators. It satisfies the requirement for a freely accessible external source that enriches incident response context.
- ✗
Internal network traffic logs
Why it's wrong here
Internal network traffic logs record the organisation's own activity, not external adversary tradecraft, so they support detection and forensics rather than threat intelligence. They are tempting because logs are central to incident response, but threat intelligence requires external context about actors, campaigns, and indicators.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.