nerdexam
Cisco

300-710 · Question #127

A network engineer wants to add a third-party threat feed into the Cisco FMC for enhanced threat detection Which action should be taken to accomplish this goal?

The correct answer is A. Enable Threat Intelligence Director using STIX and TAXII. Cisco Firepower Management Center (FMC) includes a feature called Threat Intelligence Director (TID) specifically designed to ingest third-party threat intelligence feeds. TID uses industry-standard protocols: STIX (Structured Threat Information eXpression) for representing…

Integration

Question

A network engineer wants to add a third-party threat feed into the Cisco FMC for enhanced threat detection Which action should be taken to accomplish this goal?

Options

  • AEnable Threat Intelligence Director using STIX and TAXII
  • BEnable Rapid Threat Containment using REST APIs
  • CEnable Threat Intelligence Director using REST APIs
  • DEnable Rapid Threat Containment using STIX and TAXII

How the community answered

(37 responses)
  • A
    95% (35)
  • B
    3% (1)
  • C
    3% (1)

Explanation

Cisco Firepower Management Center (FMC) includes a feature called Threat Intelligence Director (TID) specifically designed to ingest third-party threat intelligence feeds. TID uses industry-standard protocols: STIX (Structured Threat Information eXpression) for representing threat data and TAXII (Trusted Automated eXchange of Intelligence Information) for transporting that data. Together, STIX/TAXII form the backbone of modern threat intelligence sharing. Rapid Threat Containment (RTC) is a different feature used to automate quarantine responses via ISE integration - it does not handle threat feed ingestion. REST APIs are used for programmatic FMC management, not for threat intelligence feed intake.

Topics

#Threat Intelligence Director#STIX/TAXII#Threat Feeds#Cisco FMC

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice