C1000-163 · Question #121
Which app pulls feeds by using the open standard STIX and TAXII formats?
The correct answer is B. QRadar Threat Intelligence. QRadar Threat Intelligence is correct because it is specifically designed to ingest and process threat intelligence feeds using STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Intelligence Information) - the two open standards for…
Question
Which app pulls feeds by using the open standard STIX and TAXII formats?
Options
- AQRadar Use Case Manager
- BQRadar Threat Intelligence
- CQRadar User Behavior Analytics
- DQRadar Network Threat Analytics
How the community answered
(52 responses)- A2% (1)
- B81% (42)
- C6% (3)
- D12% (6)
Explanation
QRadar Threat Intelligence is correct because it is specifically designed to ingest and process threat intelligence feeds using STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated eXchange of Intelligence Information) - the two open standards for sharing cyber threat data between organizations and tools.
The distractors target related but distinct functions: Use Case Manager (A) helps build and manage detection rules and use cases within QRadar, not consume threat feeds. User Behavior Analytics (C) focuses on detecting anomalous user activity through machine learning, not external threat feed ingestion. Network Threat Analytics (D) analyzes network traffic patterns to detect threats, again unrelated to pulling STIX/TAXII feeds.
Memory tip: Think "Threat Intelligence → TAXII/Intelligence feeds" - the word "Intelligence" in the app name is your clue that it handles external threat intelligence formats like STIX and TAXII.
Topics
Community Discussion
No community discussion yet for this question.