200-201 Security Policies and Procedures Practice Question
An organization is implementing a threat intelligence sharing program. Which THREE elements are commonly used standards or platforms for sharing threat intelligence?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
MISP
MISP (Malware Information Sharing Platform) is correct because it is a widely used open-source threat intelligence platform that enables organizations to store, correlate, and share indicators of compromise and threat data with trusted partners. TAXII (Trusted Automated Exchange of Intelligence Information) is correct because it is the OASIS-defined application-layer protocol specifically designed to transport cyber threat intelligence over HTTPS between parties. STIX (Structured Threat Information Expression) is correct because it is the standardized language/schema used to represent cyber threat intelligence in a structured, machine-readable form, and it is commonly paired with TAXII for exchange. ISACs (Information Sharing and Analysis Centers) are sector-specific sharing organizations rather than a technical standard or platform, and OpenIOC is a proprietary Mandiant indicator format that never became a broadly adopted sharing standard, so neither belongs here.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
MISP
Why this is correct
MISP is an open-source threat intelligence sharing platform where organisations exchange indicators, events and correlated attributes. It satisfies the sharing requirement by providing a common repository and community, complementing the STIX format and TAXII transport protocol named elsewhere.
- ✗
ISAC
Why it's wrong here
ISACs are sector-specific information sharing bodies, not a sharing standard or platform, so they cannot serve as a format for exchanging indicators. They are tempting because many organisations join an ISAC to receive peer threat reports, which is valuable for situational awareness but distinct from the technical standards the question asks for.
- ✓
TAXII
Why this is correct
TAXII defines the HTTPS-based transport protocol for exchanging structured cyber threat intelligence between servers and clients, carrying STIX-formatted content. It satisfies the interoperability requirement for automated sharing, letting the organisation publish and consume indicators programmatically rather than through manual reports or proprietary feeds.
- ✓
STIX
Why this is correct
STIX provides a structured, machine-readable language for representing cyber threat intelligence, defining domain objects such as indicators, malware and threat actors with explicit relationships. This standardised schema satisfies the program's interoperability requirement, allowing automated exchange between platforms and partners regardless of vendor, unlike unstructured formats such as PDF reports or email.
- ✗
OpenIOC
Why it's wrong here
OpenIOC is a proprietary Mandiant indicator format, not a commonly adopted sharing standard or platform, so it fails the interoperability requirement. It is tempting because it does describe indicators of compromise in structured XML, and would suit internal indicator exchange within a Mandiant toolset rather than cross-organisational sharing.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.