312-85 · Question #38
Kim, an analyst, is looking for an intelligence-sharing platform to gather and share threat information from a variety of sources. He wants to use this information to develop security policies to…
The correct answer is D. Blueliv threat exchange network. Blueliv Threat Exchange Network (D) is a purpose-built threat intelligence sharing platform that aggregates indicators of compromise (IOCs) and threat data from multiple sources, enabling analysts like Kim to consume and share intelligence - exactly what's needed to inform…
Question
Kim, an analyst, is looking for an intelligence-sharing platform to gather and share threat information from a variety of sources. He wants to use this information to develop security policies to enhance the overall security posture of his organization. Which of the following sharing platforms should be used by Kim?
Options
- ACuckoo sandbox
- BOmniPeek
- CPortDroid network analysis
- DBlueliv threat exchange network
How the community answered
(25 responses)- A4% (1)
- C4% (1)
- D92% (23)
Explanation
Blueliv Threat Exchange Network (D) is a purpose-built threat intelligence sharing platform that aggregates indicators of compromise (IOCs) and threat data from multiple sources, enabling analysts like Kim to consume and share intelligence - exactly what's needed to inform security policy decisions.
Why the distractors are wrong:
- A. Cuckoo Sandbox is an open-source malware analysis sandbox used to detonate and analyze suspicious files in an isolated environment - it analyzes threats, it doesn't share intelligence feeds.
- B. OmniPeek is a network protocol analyzer (packet capture/inspection tool) used for troubleshooting network performance - not threat intelligence sharing.
- C. PortDroid is a mobile network scanning and analysis toolkit for Android - a reconnaissance/diagnostic tool, not a threat intel platform.
Memory tip: Associate "Blueliv" with the blue team - the defensive security side that shares and consumes threat intelligence to strengthen defenses. If a question mentions sharing threat feeds across sources to build security policy, think "blue team sharing = Blueliv."
Topics
Community Discussion
No community discussion yet for this question.