Soru

Zorluk: Çok zorThreat Intelligence Sources and Research

A senior Security Operations Center (SOC) analyst is designing an automated threat intelligence sharing pipeline between an enterprise SIEM and a regional Information Sharing and Analysis Center (ISAC). The requirement dictates establishing an automated, machine-readable mechanism capable of transporting standardized indicators of compromise (IoCs) and threat actor context over HTTPS. Which combination of technical standards and protocols best fulfills this architectural requirement?

  1. Utilizing TAXII as the application-layer transport protocol to exchange threat intelligence packaged in STIX format.Cevap
  2. B
    Utilizing STIX as the network transport protocol to pull raw OSINT threat feeds formatted in OpenIOC XML schemas.
  3. C
    Utilizing OpenIOC as the secure transport payload mechanism to push automated ISAC feeds directly via CVE vulnerability databases.
  4. D
    Utilizing Automated Indicator Sharing (AIS) as the underlying data serialization format delivered over TLS directly to edge firewalls for rule execution.

Cevap

Utilizing TAXII as the application-layer transport protocol to exchange threat intelligence packaged in STIX format.
The combination of TAXII and STIX fulfills the requirement for automated threat intelligence sharing. STIX provides the structured, machine-readable format (JSON/XML) for representing threat concepts such as attack patterns, threat actors, and indicators. TAXII acts as the dedicated HTTPS web service protocol that transports STIX intelligence between organizations, such as an ISAC and a subscriber's SIEM.

Adım Adım Çözüm

1
Analyze the operational requirement for automated threat intelligence sharing.
Identified the need for both a machine-readable data serialization format and a secure transport protocol capable of operating over web standards (HTTPS).
Threat intelligence sharing requires decoupling the information structure from the transport layer mechanism.
2
Evaluate the functional roles of STIX and TAXII.
STIX defines 'what' is being expressed (the threat language schema), and TAXII defines 'how' that information is communicated automatedly over the network.
CompTIA Security+ standards strictly differentiate between structured threat architecture (STIX) and transport services (TAXII).
3
Select the correct combination matching the scenario constraints.
TAXII transports STIX-packaged threat intelligence between the enterprise SIEM and the regional ISAC.
This standardized pairing ensures seamless interoperability across automated security platforms.

Anahtar Kavram

STIX/TAXII Threat Intelligence Standards
Tahmini Süre:2m 0s
Bu soruyu puanla