Soru

Zorluk: OrtaThreat Intelligence Sources and Research

Following an industry-wide software supply chain incident, an enterprise incident response director wants to enable real-time ingestion of machine-readable indicators of compromise from trusted peer organizations. The technical requirements specify establishing automated client-server polling over encrypted HTTPS connections to retrieve structured threat feeds directly into defensive gateway controls. Which standard provides the transport mechanism required to support this automated intelligence exchange?

  1. TAXII (Trusted Automated eXchange of Intelligence Information)Cevap
  2. B
    STIX (Structured Threat Information eXpress)
  3. C
    OpenIOC
  4. D
    CVE (Common Vulnerabilities and Exposures)

Cevap

TAXII (Trusted Automated eXchange of Intelligence Information)
TAXII (Trusted Automated eXchange of Intelligence Information) is an application-layer protocol designed to securely exchange cyber threat intelligence over HTTPS. It defines RESTful web service specifications (such as collection polling and channel subscriptions) that enable automated sharing of machine-readable threat data between organizations.

Adım Adım Çözüm

1
Identify the operational requirement outlined in the scenario.
The scenario requires an automated network transport protocol capable of sharing threat data over HTTPS RESTful services.
Differentiating between intelligence data formatting and network transport standards is required when architecting automated ingestion feeds.
2
Distinguish between data representation standards and transport mechanisms.
STIX provides the structured language/format (JSON/XML objects), while TAXII provides the actual messaging and transport protocols over HTTPS.
TAXII defines specific client-server interaction models (such as collection polling and channel subscriptions) to deliver intelligence securely.

Anahtar Kavram

Threat Intelligence Transport Protocols vs. Serialization Formats
Tahmini Süre:1m 30s
Bu soruyu puanla