350-201 Question 89
Select 3An organization is using a Threat Intelligence Platform (TIP) to enhance its cybersecurity operations. The security team wants to automate the ingestion of threat intelligence feeds and the distribution of actionable intelligence to their SIEM and firewall for proactive threat detection and mitigation. Which of the following functionalities provided by a TIP would best support this automation?
- A
Integration with external threat intelligence feeds using APIs
- B
Automated enrichment of threat data with context such as geolocation and reputation
- C
Manual export of threat intelligence reports to CSV for distribution
- D
Publishing threat intelligence findings to internal security tools like SIEM and firewalls
- E
Real-time collaboration among analysts using a TIP chat feature
Show answer and explanation
Correct answers: A, B, D
Explanation
A Threat Intelligence Platform (TIP) is designed to automate the collection, enrichment, and dissemination of threat intelligence. Integration with external feeds, automated enrichment of threat data, and publishing actionable intelligence to internal tools like SIEMs and firewalls are key functionalities that enable automation. These features help streamline threat detection and mitigation processes, reducing manual effort and response times.
- A. Correct.
Integration with external threat intelligence feeds using APIs allows the TIP to continuously and automatically ingest data from various threat intelligence sources, which is crucial for automation.
- B. Correct.
Automated enrichment of threat data provides actionable intelligence by adding context to raw data, such as identifying geolocation or reputation of IPs or domains, which helps in decision-making.
- C. Incorrect.
Manual export of threat intelligence reports is not an automated process and contradicts the goal of automating intelligence workflows.
- D. Correct.
Publishing threat intelligence findings to internal tools like SIEM and firewalls ensures that actionable intelligence is distributed automatically to tools that can act on it.
- E. Incorrect.
Real-time collaboration among analysts is a useful feature for discussing intelligence, but it does not directly contribute to automating threat intelligence ingestion and distribution.