The Demon Queen would like to provide a dumbed downed explanation as why it is D.
The "uploads" part of the question can easily throw you off as it seems like it is sharing Threat intelligence will other orgs. However that is not the case as the term "upload" refers to the TIDirector pushing out processed threat intelligence data to sensors on the network to look out for in this case block listed items. How it works?
Threat Intelligence Directory first consumes threat intelligence data and processes it before uploading (pushing or sending) it out to sensors on the network to detect the newly uploaded info.
D is correct!
--Consume is the keyword!
Cisco Threat Intelligence Director (TID) is a system that operationalizes threat intelligence information. The system consumes and normalizes heterogeneous third-party cyber threat intelligence, publishes the intelligence to detection technologies, and correlates the observations from the detection technologies.
https://www.cisco.com/c/en/us/support/docs/storage-networking/security/214859-configure-and-troubleshoot-cisco-threat.html
D is correct!
--Consume is the keyword!
Cisco Threat Intelligence Director (TID) is a system that operationalizes threat intelligence information. The system consumes and normalizes heterogeneous third-party cyber threat intelligence, publishes the intelligence to detection technologies, and correlates the observations from the detection technologies.
https://www.cisco.com/c/en/us/support/docs/storage-networking/security/214859-configure-and-troubleshoot-cisco-threat.html
There are two new terms:
STIX (Structured Threat Intelligence eXpression) is a standard for sharing and using threat intelligence information. There are three key functional elements: Indicators, Observables, and Incidents
TAXII (Trusted Automated eXchange of Indicator Information) is a transport mechanism for threat information
check out the diagram in figure 2 https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/cisco_threat_intelligence_director__tid_.html
B looks correct.
The question says: "allows uploads and downloads of block lists", which is the method of sharing. Consumption always means downloading the block list.
I've looked at multiple sources for this one, it's definitely 'D' - Consumption:
"TID has the ability to 'consume' threat intelligence via STIX over TAXII and allows uploads/downloads of STIX and simple blacklists.
Editing, is not the correct answer because editing refers to the process of modifying existing STIX-compliant threat intelligence data, rather than creating new data or sharing it with other security platforms.
Sharing, is also not the correct answer because while sharing is an important aspect of the STIX format, it does not specifically refer to the process of using STIX to create or update block lists.
Consumption, is not the correct answer because consumption refers to the process of using STIX threat intelligence data to inform security policies or other security-related decisions, rather than the process of creating or updating block lists based on STIX data.
It is Consumption.
---
https://www.cisco.com/c/en/us/support/docs/storage-networking/security/214859-configure-and-troubleshoot-cisco-threat.html
---
Cisco Threat Intelligence Director (TID) is a system that operationalizes threat intelligence information. The system consumes and normalizes heterogeneous third-party cyber threat intelligence, publishes the intelligence to detection technologies and correlates the observations from the detection technologies.
Isn't D - Consumption?
The answer is consumption (B) - https://blogs.cisco.com/developer/automate-threat-intelligence-using-cisco-threat-intelligence-director
"TID has the ability to consume threat intelligence via STIX over TAXII and allows uploads/downloads of STIX and simple blacklists"
This section is not available anymore. Please use the main Exam Page.350-701 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Demon_Queen_Velverosa
7 months, 3 weeks agobfd04b6
9 months agobfd04b6
9 months agoc946f3e
1 year, 8 months agonep1019
1 year, 9 months agoums008
1 year, 10 months agoJessie45785
1 year, 11 months agoMPoels
1 year, 2 months agoezpzls
1 year, 12 months agoalischajan
2 years, 1 month agoTotosos1
2 years, 1 month agodawlims
2 years, 1 month agoachille5
2 years, 2 months agoachille5
2 years, 2 months agoAnonymous983475
2 years, 4 months agoCCNP21
2 years, 4 months agoEmlia1
2 years, 5 months agoEmlia1
2 years, 5 months agoedu_web
2 years, 5 months ago