300-740 · Question #66
Which component of the Cisco Security Reference Architecture focuses on identifying and analyzing threats?
The correct answer is A. Threat intelligence. Threat Intelligence (A) is the component specifically designed to identify, collect, and analyze threat data - it's the "eyes and ears" of the security architecture, focused on understanding adversaries, their tactics, and indicators of compromise. B (Network security) is wrong…
Question
Which component of the Cisco Security Reference Architecture focuses on identifying and analyzing threats?
Options
- AThreat intelligence
- BNetwork security
- CUser/device security
- DSecurity operations toolset
How the community answered
(68 responses)- A91% (62)
- B4% (3)
- C3% (2)
- D1% (1)
Explanation
Threat Intelligence (A) is the component specifically designed to identify, collect, and analyze threat data - it's the "eyes and ears" of the security architecture, focused on understanding adversaries, their tactics, and indicators of compromise.
B (Network security) is wrong because it focuses on protecting the network infrastructure itself (firewalls, segmentation, traffic control), not on analyzing threats. C (User/device security) covers endpoint protection and identity management - securing who and what connects, not analyzing threat patterns. D (Security operations toolset) refers to the tools used to respond to incidents (SIEM, SOAR, etc.), which is reactive operations rather than proactive threat identification.
Memory tip: Think of Threat Intelligence = "Know your enemy." It's the reconnaissance layer - gathering and analyzing information about threats before or during an attack, which maps directly to the word "intelligence" (information gathered through analysis).
Topics
Community Discussion
No community discussion yet for this question.