350-201 Question 92
Select 3A cybersecurity team uses a Threat Intelligence Platform (TIP) to enhance their incident response workflow. Which of the following actions can be automated using a TIP to improve operational efficiency?
- A
Ingesting threat intelligence feeds from multiple sources
- B
Automatically blocking malicious IPs on firewalls without human approval
- C
Correlating threat data with internal logs to identify potential attacks
- D
Sending enriched threat intelligence to a SIEM for further analysis
- E
Manually analyzing threat reports for decision-making
Show answer and explanation
Correct answers: A, C, D
Explanation
Threat Intelligence Platforms (TIPs) are designed to automate the ingestion, correlation, and enrichment of threat data from various sources to support security teams in identifying and mitigating threats more efficiently. While TIPs can integrate with other tools for actions like blocking malicious IPs, they typically don't operate without human oversight for those tasks. Their primary role is to enhance data processing and streamline workflows, allowing for better decision-making and integration with other systems such as SIEMs.
- A. Correct.
A TIP is designed to ingest threat intelligence feeds from various external sources, which is a key part of its functionality.
- B. Incorrect.
While a TIP can provide actionable intelligence, automated blocking typically requires integration with other security tools and often involves human oversight to avoid false positives.
- C. Correct.
Correlation of threat data with internal logs is a critical function of a TIP, enabling the detection of potential threats through contextual analysis.
- D. Correct.
Sending enriched threat data to tools like SIEMs is a common use case for a TIP to ensure comprehensive threat monitoring and analysis.
- E. Incorrect.
Manual analysis is not typically automated by a TIP. Instead, a TIP is used to reduce the need for manual work by automating data collection, correlation, and enrichment.