Question

Difficulty: Very hardThreat Intelligence Sources and Research

An enterprise financial institution plans to automate the ingestion of machine-readable threat indicators specifically sourced from peer sector organizations while standardizing automated indicator transport into its Security Orchestration, Automation, and Response (SOAR) platform. Which of the following solutions should the cybersecurity team implement to achieve these specific objectives? (Select TWO.)

  1. Financial Services Information Sharing and Analysis Center (FS-ISAC) subscriptionAnswer
  2. Trusted Automated eXchange of Intelligence Information (TAXII) feed integrationAnswer
  3. C
    National Vulnerability Database (NVD) data feeds
  4. D
    Strategic threat intelligence executive briefings
  5. E
    Manual Open Source Intelligence (OSINT) RSS blog scrapers

Answer

The cybersecurity team should implement a Financial Services Information Sharing and Analysis Center (FS-ISAC) subscription and a Trusted Automated eXchange of Intelligence Information (TAXII) feed integration.
To fulfill the requirements, the organization needs both a sector-specific community threat source and an automated protocol for machine-readable ingestion. Subscribing to an Information Sharing and Analysis Center (specifically FS-ISAC for financial entities) supplies specialized threat data from peer institutions. Integrating a TAXII feed provides the standardized, machine-to-machine RESTful transport protocol needed to automatically ingest structured threat data directly into security orchestration platforms.

Step-by-Step Solution

1
Identify the requirement for sector-specific peer intelligence sharing.
Determined that joining an ISAC (such as FS-ISAC) provides vetted threat intelligence specifically tailored to and shared by peer institutions within the financial sector.
ISACs facilitate targeted industry information sharing regarding sector-relevant attack vectors and active campaigns.
2
Identify the protocol mechanism required for machine-readable, automated threat indicator transport.
Selected TAXII as the automated transport mechanism to push and pull threat data directly into the SOAR platform.
TAXII is specifically built to automate the secure exchange of structured threat intelligence data feeds across networks.
3
Evaluate alternative options for alignment with automation and sector specificity.
Disqualified NVD feeds (vulnerability focus, not threat indicators), strategic briefings (high-level executive human reports, not machine-readable), and manual OSINT RSS scrapers (unstructured human-readable blog data).
These alternatives fail to meet the dual criteria of sector-specific peer intelligence sharing and automated machine-readable transport.

Key Concept

Threat Intelligence Sharing Architectures (ISACs and TAXII)
Rate this question