nerdexam
EC-Council

312-39 · Question #50

A multinational cybersecurity firm wants to enhance its threat intelligence capabilities by integrating real-time threat feeds into Microsoft Sentinel. These feeds include malicious IPs, domains, file

Sign in or unlock 312-39 to reveal the answer and full explanation for question #50. The question stem and answer options stay visible for context.

Threat Intelligence

Question

A multinational cybersecurity firm wants to enhance its threat intelligence capabilities by integrating real-time threat feeds into Microsoft Sentinel. These feeds include malicious IPs, domains, file hashes, and attack patterns. The firm requires a standardized protocol that allows automated threat intelligence sharing so Sentinel continuously receives updated indicators from external sources in a structured format. Which Microsoft Sentinel data connector should be implemented to integrate threat intelligence feeds using an industry-standard protocol?

Options

  • AThreat Intelligence Platforms data connector
  • BSyslog connector
  • CTAXII data connector
  • DMicrosoft Defender for Cloud (Legacy) connector

Unlock 312-39 to see the answer

You've previewed enough free 312-39 questions. Unlock 312-39 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Microsoft Sentinel#TAXII connector#threat intelligence feeds#IOC integration
Full 312-39 Practice