Courseiva

200-201 Security Policies and Procedures Practice Question

A security analyst needs to share threat intelligence with other organizations in a standardized, machine-readable format. Which combination of standards should the analyst use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

STIX and TAXII

STIX is a language for threat intelligence, and TAXII is a protocol for sharing it. They are commonly used together.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    TAXII and MISP

    Why it's wrong here

    TAXII is the correct transport protocol, but MISP is a sharing platform, not the structured data model. The pair is tempting because MISP does support TAXII, yet the question asks for standards, and STIX supplies the machine-readable representation that TAXII carries.

  • ✓

    STIX and TAXII

    Why this is correct

    STIX provides the structured, machine-readable schema for describing indicators, threat actors and campaigns, while TAXII defines the transport protocol for exchanging that content between parties. Together they satisfy the requirement for standardised, automated threat-intelligence sharing.

  • ✗

    ISAC and STIX

    Why it's wrong here

    An ISAC is an information-sharing organisation, not a technical standard, so it cannot encode or transport indicators. It is tempting because ISACs are the bodies through which organisations share intelligence, but the machine-readable format and transport must come from STIX and TAXII.

  • ✗

    OpenIOC and MISP

    Why it's wrong here

    OpenIOC is a proprietary Mandiant indicator format, not a ratified sharing standard, and MISP is a platform rather than a transport or data model. The pairing tempts because both appear in threat-intel tooling, yet neither provides the STIX data model with TAXII transport that machine-readable exchange requires.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.