Soru

Zorluk: ZorThreat Intelligence Sources and Research

A senior threat intelligence analyst at a global financial services firm is architecting an automated threat feed ingestion pipeline. The system must standardize machine-readable cyber threat indicators and automatically transport them directly into the enterprise Security Information and Event Management (SIEM) platform for real-time correlation without requiring manual analyst intervention. Which of the following standards or protocol frameworks are specifically designed to meet these requirements? (Select TWO.)

  1. STIX (Structured Threat Information eXpression) to standardize the serialization and language schema of the threat indicators.Cevap
  2. TAXII (Trusted Automated eXchange of Intelligence Information) to establish the automated transport protocol for transmitting threat feeds over HTTPS.Cevap
  3. C
    NVD (National Vulnerability Database) feed integration to automatically modify perimeter firewall rules based on newly published CVSS scores.
  4. D
    ISAC (Information Sharing and Analysis Center) email advisory bulletins to profile actor motivations prior to automated ingestion.
  5. E
    OSINT web scraping feeds targeting public threat forums to automatically deploy preventive endpoint blocking rules.

Cevap

STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Intelligence Information) are the required standards for establishing an automated, machine-readable threat intelligence ingestion pipeline.
Building an automated threat intelligence ingestion pipeline requires both a standardized data structure and a secure transport protocol. STIX specifies the standardized, machine-readable format (such as JSON) for representing indicators and threat context. TAXII acts as the dedicated transport mechanism operating over HTTPS to exchange STIX-packaged intelligence between systems automatically.

Adım Adım Çözüm

1
Identify the data format requirement for machine-readable indicator standardization.
STIX (Structured Threat Information eXpression) defines the structured taxonomy and serialization format (JSON/XML) for threat indicators.
SIEM and SOAR tools require a unified schema to programmatically parse and correlate threat data from multiple sources.
2
Identify the transmission protocol requirement for automated delivery.
TAXII (Trusted Automated eXchange of Intelligence Information) provides the API and transport mechanism over HTTPS to push or pull STIX data automatically.
Automated ingestion requires an application-layer protocol designed specifically for cyber threat intelligence exchanges.
3
Evaluate and eliminate non-automated or misaligned intelligence sources.
NVD feeds focus on vulnerability scoring rather than threat indicators, ISAC email bulletins require manual human reading, and raw OSINT scraping lacks structured machine readability.
None of these alternatives satisfy both automated transport and standardized machine-readable threat representation.

Anahtar Kavram

STIX and TAXII standards for automated threat intelligence ingestion
Bu soruyu puanla