200-201 Security Policies and Procedures Practice Question
An organization is implementing a threat intelligence sharing program. They want to exchange both structured indicators and full reports with other members of their ISAC. Which combination of standards/protocols should they choose? (Choose two.)
⚠ Common exam trap
Cisco often tests the distinction between a data model (STIX) and a transport protocol (TAXII), and candidates mistakenly choose MISP as a standard instead of recognizing it as a platform that implements these standards.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
TAXII
STIX (Structured Threat Information Expression) is the standard for representing structured threat indicators and full reports, enabling both machine-readable indicators and human-readable context. TAXII (Trusted Automated Exchange of Indicator Information) is the transport protocol that defines how STIX content is exchanged over HTTPS. Together, they allow ISAC members to share threat intelligence in a standardized, automated manner. Snort rules are signatures for intrusion detection, not a sharing standard. OpenIOC is a format for indicators but lacks the report capability and transport protocol. MISP is a platform that can use STIX/TAXII but is not itself a standard or protocol.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Snort rules
Why it's wrong here
Snort rules are a detection signature format for IDS/IPS engines, not a sharing standard for structured indicators or full reports. They are tempting because they encode threat logic, and would be correct when deploying intrusion detection, whereas STIX and TAXII serve indicator exchange and transport.
- ✓
TAXII
Why this is correct
TAXII provides the transport mechanism for exchanging cyber threat intelligence over HTTPS, supporting both structured indicators and full reports through its collections and channels model. It satisfies the ISAC sharing requirement by enabling automated, bidirectional exchange between members, complementing STIX's data representation with the delivery protocol needed for programmatic sharing.
- ✗
OpenIOC
Why it's wrong here
OpenIOC is a Mandiant indicator format for host-based compromise artefacts, not a transport protocol for sharing full reports between ISAC members. It is tempting because it structures indicators such as file hashes and registry keys, which suits endpoint detection, yet it cannot carry the narrative report content the scenario requires.
- ✓
STIX
Why this is correct
STIX provides the structured, machine-readable schema for cyber threat indicators, enabling automated ingestion and correlation across ISAC members. It satisfies the requirement to exchange structured indicators by defining standardised objects such as indicators, observables and relationships, which TAXII then transports. Full reports, however, require a separate standard.
- ✗
MISP
Why it's wrong here
MISP is a threat intelligence platform, not a standard for exchanging full reports; it consumes and produces STIX/TAXII data rather than defining the exchange format itself. It is tempting because MISP genuinely aggregates and shares structured indicators across ISAC members, but the question asks for the standards/protocols enabling both indicator and report exchange.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.