Soru

Zorluk: ZorThreat Intelligence Sources and Research

A threat intelligence team at a healthcare enterprise is designing an automated threat indicator pipeline. The organization wants to ingest structured, machine-readable threat data from trusted peer organizations within its industry sector and automatically exchange standardized operational telemetry across security platforms in real time. Which of the following solutions should the team implement to fulfill these specific requirements? (Select TWO.)

  1. Deployment of TAXII protocol services to facilitate automated, machine-readable indicator transport between security systems.Cevap
  2. Direct subscription and participation in a sector-specific ISAC to receive and share industry-relevant threat telemetry with peer organizations.Cevap
  3. C
    Automated blocking rules configured on perimeter firewalls driven directly by unparsed National Vulnerability Database (NVD) CVE entry updates.
  4. D
    Configuring honeypot deception systems to act as primary inline packet-filtering firewalls for production network segments.
  5. E
    Restructuring endpoint detection rules under the assumption that low-skilled script kiddies execute customized zero-day targeted nation-state campaigns.

Cevap

The correct solutions are deploying TAXII protocol services for automated indicator transport and joining a sector-specific ISAC to exchange vetted threat data with industry peers.
To achieve automated, machine-readable threat indicator ingestion and real-time community sharing, an organization should deploy TAXII servers (which manage the transport layer for structured threat data such as STIX) and participate in a sector-specific ISAC (which provides the operational trust framework and platform for industry peers to exchange relevant telemetry).

Adım Adım Çözüm

1
Analyze requirement for automated, real-time indicators
Identify that machine-readable threat indicator transport requires standardized protocol exchange standards like TAXII.
TAXII automates the sharing of structured threat data across heterogeneous security systems.
2
Analyze requirement for peer-to-peer industry indicator sharing
Identify that sector-specific threat sharing relies on Information Sharing and Analysis Centers (ISACs).
ISACs enable trusted peer collaboration and targeted threat intelligence dissemination within specialized domains like healthcare.
3
Evaluate distractor choices against threat intel definitions
Reject CVE/NVD unparsed feeds for firewall blocking, honeypots for inline packet filtering, and misaligned threat actor attribution.
Vulnerability databases do not contain active operational IOCs, honeypots are not preventive filtering controls, and script kiddies lack zero-day targeted capability.

Anahtar Kavram

Threat Intelligence Sharing Architecture (ISACs and TAXII)
Bu soruyu puanla