Courseiva

200-201 Security Policies and Procedures Practice Question

An organization is implementing a threat intelligence sharing program. Which THREE elements are commonly used standards or platforms for sharing threat intelligence?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

MISP

MISP (Malware Information Sharing Platform) is correct because it is a widely used open-source threat intelligence platform that enables organizations to store, correlate, and share indicators of compromise and threat data with trusted partners. TAXII (Trusted Automated Exchange of Intelligence Information) is correct because it is the OASIS-defined application-layer protocol specifically designed to transport cyber threat intelligence over HTTPS between parties. STIX (Structured Threat Information Expression) is correct because it is the standardized language/schema used to represent cyber threat intelligence in a structured, machine-readable form, and it is commonly paired with TAXII for exchange. ISACs (Information Sharing and Analysis Centers) are sector-specific sharing organizations rather than a technical standard or platform, and OpenIOC is a proprietary Mandiant indicator format that never became a broadly adopted sharing standard, so neither belongs here.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    MISP

    Why this is correct

    MISP is an open-source threat intelligence sharing platform where organisations exchange indicators, events and correlated attributes. It satisfies the sharing requirement by providing a common repository and community, complementing the STIX format and TAXII transport protocol named elsewhere.

  • ✗

    ISAC

    Why it's wrong here

    ISACs are sector-specific information sharing bodies, not a sharing standard or platform, so they cannot serve as a format for exchanging indicators. They are tempting because many organisations join an ISAC to receive peer threat reports, which is valuable for situational awareness but distinct from the technical standards the question asks for.

  • ✓

    TAXII

    Why this is correct

    TAXII defines the HTTPS-based transport protocol for exchanging structured cyber threat intelligence between servers and clients, carrying STIX-formatted content. It satisfies the interoperability requirement for automated sharing, letting the organisation publish and consume indicators programmatically rather than through manual reports or proprietary feeds.

  • ✓

    STIX

    Why this is correct

    STIX provides a structured, machine-readable language for representing cyber threat intelligence, defining domain objects such as indicators, malware and threat actors with explicit relationships. This standardised schema satisfies the program's interoperability requirement, allowing automated exchange between platforms and partners regardless of vendor, unlike unstructured formats such as PDF reports or email.

  • ✗

    OpenIOC

    Why it's wrong here

    OpenIOC is a proprietary Mandiant indicator format, not a commonly adopted sharing standard or platform, so it fails the interoperability requirement. It is tempting because it does describe indicators of compromise in structured XML, and would suit internal indicator exchange within a Mandiant toolset rather than cross-organisational sharing.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.