A security engineering team is automating its enterprise threat intelligence workflow to improve SIEM alert enrichment. The solution requires a standardized data format for expressing structured cyber threat information alongside an automated protocol for machine-to-machine transport over HTTPS. Which of the following standards should the team implement to satisfy these requirements? (Select TWO.)
- STIX (Structured Threat Information eXpression)Cevap
- TAXII (Trusted Automated eXchange of Intelligence Information)Cevap
- CCVE (Common Vulnerabilities and Exposures) dictionary index
- DAutomated OSINT web scraping scripts targeting open forums
- EManual ISAC security bulletin emails
Cevap
The team should implement STIX for standardized threat data representation and TAXII for automated machine-to-machine transport.
The combination of STIX and TAXII enables end-to-end automation of threat intelligence pipelines. STIX provides the structured language (JSON-based schema) to represent threat concepts, while TAXII defines the web services and protocols to transmit that structured data reliably between systems.
Adım Adım Çözüm
Anahtar Kavram
STIX/TAXII Threat Intelligence Standards
Tahmini Süre:1m 30s