Soru

Zorluk: OrtaThreat Intelligence Sources and Research

A security engineering team is automating its enterprise threat intelligence workflow to improve SIEM alert enrichment. The solution requires a standardized data format for expressing structured cyber threat information alongside an automated protocol for machine-to-machine transport over HTTPS. Which of the following standards should the team implement to satisfy these requirements? (Select TWO.)

  1. STIX (Structured Threat Information eXpression)Cevap
  2. TAXII (Trusted Automated eXchange of Intelligence Information)Cevap
  3. C
    CVE (Common Vulnerabilities and Exposures) dictionary index
  4. D
    Automated OSINT web scraping scripts targeting open forums
  5. E
    Manual ISAC security bulletin emails

Cevap

The team should implement STIX for standardized threat data representation and TAXII for automated machine-to-machine transport.
The combination of STIX and TAXII enables end-to-end automation of threat intelligence pipelines. STIX provides the structured language (JSON-based schema) to represent threat concepts, while TAXII defines the web services and protocols to transmit that structured data reliably between systems.

Adım Adım Çözüm

1
Identify the data format requirement
STIX (Structured Threat Information eXpression) is selected as the standardized language to represent cyber threat data objects.
STIX defines standardized structures for threat indicators, tactics, techniques, and procedures (TTPs).
2
Identify the automated transport protocol requirement
TAXII (Trusted Automated eXchange of Intelligence Information) is selected to transmit STIX-formatted intelligence over HTTPS.
TAXII is designed specifically to support secure machine-to-machine exchange of STIX content without human intervention.

Anahtar Kavram

STIX/TAXII Threat Intelligence Standards
Tahmini Süre:1m 30s
Bu soruyu puanla