Soru

Zorluk: OrtaThreat Intelligence Sources and Research

A security engineering team is implementing an automated threat intelligence platform to exchange structured cyber threat data with an industry ISAC and ingest machine-readable indicators into internal security tools. Which of the following components specifically define the standardized language for expressing threat data and the automated transport protocol for exchanging it? (Select TWO.)

  1. STIX (Structured Threat Information eXpression)Cevap
  2. TAXII (Trusted Automated eXchange of Indicator Information)Cevap
  3. C
    CVE (Common Vulnerabilities and Exposures)
  4. D
    Honeypot network deployment
  5. E
    Firewall access control list (ACL) rules

Cevap

STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Indicator Information)
Structured Threat Information eXpression defines the standardized schema for representing threat intelligence in a consistent machine-readable format, while Trusted Automated eXchange of Indicator Information defines the automated transport protocol for exchanging that intelligence over HTTPS.

Adım Adım Çözüm

1
Identify the data representation standard required for machine-readable threat intelligence.
STIX provides the standardized XML/JSON schema for describing cyber threat indicators, threat actors, and attack patterns.
Security tools require a consistent data structure to parse and act upon external threat intelligence automatically.
2
Identify the transport mechanism designed to deliver structured threat feeds between systems.
TAXII defines the web service specifications and API protocols for securely transferring STIX threat data over HTTPS.
Automated ingestion requires a standardized messaging and transport protocol to push and pull threat data.
3
Evaluate the incorrect options against threat intelligence sharing specifications.
CVE indexes known software flaws, honeypots gather raw local telemetry via deception, and firewall ACLs enforce traffic policy; none of these serve as threat sharing data formats or transport protocols.
Differentiating threat data representation/transport mechanisms from vulnerability dictionaries, threat collection systems, and network controls ensures proper threat intel pipeline architecture.

Anahtar Kavram

STIX/TAXII Threat Intelligence Standards
Tahmini Süre:1m 30s
Bu soruyu puanla