PCCET · Question #234
How does Cortex XSOAR Threat Intelligence Management (TIM) provide relevant threat data to analysts?
The correct answer is D. II automates the ingestion and aggregation of indicators. Option D is correct because Cortex XSOAR TIM's core function is automating the collection, ingestion, and aggregation of threat indicators (IPs, domains, hashes, URLs, etc.) from multiple external and internal feeds, normalizing them so analysts can act on relevant, up-to-date…
Question
How does Cortex XSOAR Threat Intelligence Management (TIM) provide relevant threat data to analysts?
Options
- AIt creates an encrypted connection to the company's data center.
- BIt performs SSL decryption to give visibility into user traffic.
- CII prevents sensitive data from leaving the network.
- DII automates the ingestion and aggregation of indicators.
How the community answered
(28 responses)- A4% (1)
- B7% (2)
- C4% (1)
- D86% (24)
Explanation
Option D is correct because Cortex XSOAR TIM's core function is automating the collection, ingestion, and aggregation of threat indicators (IPs, domains, hashes, URLs, etc.) from multiple external and internal feeds, normalizing them so analysts can act on relevant, up-to-date threat data without manual effort.
Options A, B, and C describe unrelated security functions: encrypted connections to data centers (A) describe VPN or secure networking tools; SSL decryption for traffic visibility (B) is a feature of Next-Generation Firewalls or web proxies; and preventing sensitive data from leaving the network (C) describes Data Loss Prevention (DLP) solutions - none of which are TIM capabilities.
Memory tip: Think of TIM as a "threat data funnel" - its job is to pull in and organize indicators of compromise (IoCs) from many sources into one place, turning raw threat feeds into analyst-ready intelligence. If an answer describes collecting and processing threat indicators, that's TIM.
Topics
Community Discussion
No community discussion yet for this question.