ExamGecko
Question list
Search
Search

Question 149 - PCCET discussion

Report
Export

How does Cortex XSOAR Threat Intelligence Management (TIM) provide relevant threat data to analysts?

A.
It creates an encrypted connection to the company's data center.
Answers
A.
It creates an encrypted connection to the company's data center.
B.
It performs SSL decryption to give visibility into user traffic.
Answers
B.
It performs SSL decryption to give visibility into user traffic.
C.
II prevents sensitive data from leaving the network.
Answers
C.
II prevents sensitive data from leaving the network.
D.
II automates the ingestion and aggregation of indicators.
Answers
D.
II automates the ingestion and aggregation of indicators.
Suggested answer: D

Explanation:

Cortex XSOAR Threat Intelligence Management (TIM) is a platform that enables security teams to manage the lifecycle of threat intelligence, from aggregation to action. One of the key features of Cortex XSOAR TIM is that it automates the ingestion and aggregation of indicators from various sources, such as threat feeds, open-source intelligence, internal data, and third-party integrations 1. Indicators are pieces of information that can be used to identify malicious activity, such as IP addresses, domains, URLs, hashes, etc. By automating the ingestion and aggregation of indicators, Cortex XSOAR TIM reduces the manual effort and time required to collect, validate, and prioritize threat data. It also enables analysts to have a unified view of the global threat landscape and the impact of threats on their network 1.

Reference: 1: Threat Intelligence Management - Palo Alto Networks 2

asked 23/09/2024
Yasser Mohamed Mohamed
45 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first