A junior security analyst is tasked with setting up an automated, machine-readable threat intelligence feed to deliver standardized cyber threat indicators directly into the organization's Security Information and Event Management (SIEM) system over HTTPS. Which of the following standards and transport protocols should the analyst implement to achieve this? (Select TWO.)
- STIX (Structured Threat Information Expression)Cevap
- TAXII (Trusted Automated Exchange of Intelligence Information)Cevap
- CCVE (Common Vulnerabilities and Exposures)
- DRADIUS (Remote Authentication Dial-In User Service)
- EOSINT (Open-Source Intelligence)
Cevap
STIX (Structured Threat Information Expression) and TAXII (Trusted Automated Exchange of Intelligence Information) should be implemented.
STIX defines the standardized structured language to describe threat data (what is being shared), while TAXII defines the secure transport protocol over HTTPS to automate the exchange of that data between systems (how it is delivered). Together, STIX and TAXII enable automated threat intelligence ingestion into SIEM platforms.
Adım Adım Çözüm
Anahtar Kavram
Automated Threat Intelligence Ingestion (STIX/TAXII)