350-201 Question 91
Select 3Your organization recently deployed a Threat Intelligence Platform (TIP) to improve its cybersecurity operations. The security team wants to automate the ingestion of threat intelligence feeds, correlate them with internal telemetry, and generate automated alerts for actionable threats. Which capabilities of a TIP should be utilized to achieve this objective?
- A
Integration with external threat intelligence feeds
- B
Automated correlation of threat data with internal logs
- C
Manual review of threat alerts by security analysts
- D
Playbook-driven automation for response actions
- E
Exporting threat intelligence to cloud storage for backup
Show answer and explanation
Correct answers: A, B, D
Explanation
A Threat Intelligence Platform (TIP) is designed to ingest, correlate, and act upon threat intelligence data. To automate intelligence effectively, it must integrate with external feeds, correlate data with internal telemetry, and utilize playbooks for automated responses. These capabilities ensure streamlined operations and faster threat mitigation, aligning with the organization's goals.
- A. Correct.
Integration with external threat intelligence feeds allows the organization to ingest up-to-date threat indicators, which is essential for proactive threat detection.
- B. Correct.
Automated correlation of threat data with internal logs enables the TIP to identify relevant threats specific to the organization's environment, reducing manual efforts and improving response time.
- C. Incorrect.
Manual review of threat alerts by security analysts is not an automated process and does not align with the goal of streamlining operations through a TIP.
- D. Correct.
Playbook-driven automation for response actions allows the TIP to execute predefined workflows, reducing the time between detection and response.
- E. Incorrect.
Exporting threat intelligence to cloud storage for backup is not directly related to automating threat intelligence or improving detection and response capabilities.