350-201 Question 90
Select 2An organization is leveraging a Threat Intelligence Platform (TIP) to improve its security posture. The security team wants to automate the identification and mitigation of potential threats by integrating TIP with their SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) platforms. Which of the following capabilities of a TIP would allow the organization to achieve this automation effectively?
- A
Aggregating threat intelligence feeds from multiple sources into a centralized repository
- B
Enabling automated enrichment of alerts from the SIEM with contextual threat intelligence data
- C
Providing manual threat analysis workflows for security analysts to investigate threats
- D
Facilitating automated playbook execution in the SOAR platform based on threat intelligence insights
- E
Offering real-time threat sharing and collaboration with external partners
Show answer and explanation
Correct answers: B, D
Explanation
To achieve automation in identifying and mitigating threats, it is critical for the TIP to enable integration with SIEM and SOAR platforms. This includes features like automated enrichment of SIEM alerts with threat intelligence and triggering automated playbooks in the SOAR platform. While other capabilities, such as aggregating feeds or sharing intelligence, are important, they do not directly enable the automation described in the scenario.
- A. Incorrect.
Aggregating threat intelligence feeds is a core function of a TIP, but it does not directly enable automation of threat identification and mitigation. It is a prerequisite for other automated processes.
- B. Correct.
Automated enrichment of alerts with contextual threat intelligence allows the SIEM to provide deeper insights about threats without requiring manual analysis, supporting automation.
- C. Incorrect.
Manual workflows are useful for investigations, but they do not contribute to automation, which is the focus of the question.
- D. Correct.
Automated playbook execution in a SOAR platform based on threat intelligence insights enables end-to-end automation for identifying and mitigating threats.
- E. Incorrect.
Real-time threat sharing enhances collaboration but does not directly contribute to the automation of processes within the organization's infrastructure as described in the scenario.