nerdexam
IBM

C1000-163 · Question #121

Which app pulls feeds by using the open standard STIX and TAXII formats?

The correct answer is B. QRadar Threat Intelligence. QRadar Threat Intelligence is correct because it is specifically designed to ingest and process threat intelligence feeds using STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Intelligence Information) - the two open standards for…

Data Source Integration

Question

Which app pulls feeds by using the open standard STIX and TAXII formats?

Options

  • AQRadar Use Case Manager
  • BQRadar Threat Intelligence
  • CQRadar User Behavior Analytics
  • DQRadar Network Threat Analytics

How the community answered

(52 responses)
  • A
    2% (1)
  • B
    81% (42)
  • C
    6% (3)
  • D
    12% (6)

Explanation

QRadar Threat Intelligence is correct because it is specifically designed to ingest and process threat intelligence feeds using STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Intelligence Information) - the two open standards for sharing cyber threat data between organizations and tools.

The distractors target related but distinct functions: Use Case Manager (A) helps build and manage detection rules and use cases within QRadar, not consume threat feeds. User Behavior Analytics (C) focuses on detecting anomalous user activity through machine learning, not external threat feed ingestion. Network Threat Analytics (D) analyzes network traffic patterns to detect threats, again unrelated to pulling STIX/TAXII feeds.

Memory tip: Think "Threat Intelligence → TAXII/Intelligence feeds" - the word "Intelligence" in the app name is your clue that it handles external threat intelligence formats like STIX and TAXII.

Topics

#STIX/TAXII feeds#Threat Intelligence#QRadar Threat Intelligence#Feed integration

Community Discussion

No community discussion yet for this question.

Full C1000-163 Practice