200-201 Security Policies and Procedures Practice Question
Which organization facilitates threat intelligence sharing among members in a specific sector, such as finance or healthcare?
⚠ Common exam trap
200-201 often tests the confusion between threat intelligence sharing organizations (ISACs) and the standards/platforms used to share intelligence (STIX, TAXII, MISP), tricking candidates into selecting a technology instead of an organization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ISAC
ISACs (Information Sharing and Analysis Centers) are sector-specific organizations that facilitate threat intelligence sharing among members in industries such as finance (FS-ISAC), healthcare (H-ISAC), and aviation. They provide a trusted forum for members to exchange threat data, best practices, and incident information relevant to their sector.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MISP
Why it's wrong here
MISP is an open-source platform for storing and sharing threat indicators, not a sector-specific organisation. It is tempting because MISP enables community sharing and is widely used by analysts, but it is a tool, whereas the question asks for the body that facilitates sharing among finance or healthcare members.
- ✓
ISAC
Why this is correct
ISACs are sector-specific non-profit organisations that collect, analyse and share threat intelligence among members within industries such as finance or healthcare. They satisfy the stem's requirement for a sector-focused sharing body, unlike cross-sector or government-led alternatives.
- ✗
STIX
Why it's wrong here
STIX is a structured language for expressing cyber threat information, not an organisation that facilitates sharing. It is tempting because STIX appears in threat-intelligence sharing discussions alongside sharing groups, but it defines data formats; the sector-based sharing bodies are ISACs, which is what the question asks for.
- ✗
TAXII
Why it's wrong here
TAXII is a transport protocol for exchanging threat intelligence over HTTPS, not an organisation. It is tempting because TAXII is named in the same sharing ecosystem as STIX and ISACs, but it specifies communication services; the sector-focused facilitating bodies are ISACs, which the question requires.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.