CompTIA CySA+ (CS0-003)Security OperationsMedium
A threat intelligence team wants to automatically share and receive structured indicators of compromise (IOCs) with an information sharing and analysis center (ISAC) using a standardized, machine-readable format transported over a defined exchange protocol. Which pair of standards should the team implement?
- AOpenIOC over FTP
- BCVSS over HTTP
- CYARA rules over SMTP
- DSTIX over TAXII
Show answer & explanationAnswer & explanation
Correct answer: D. STIX over TAXII
STIX (Structured Threat Information eXpression) defines the standardized, machine-readable format for describing threat intelligence, while TAXII (Trusted Automated eXchange of Indicator Information) defines the protocol for transporting that data between organizations—together the industry standard for automated sharing.
Why the other options are wrong
- A. OpenIOC is a format for indicators but lacks a standardized exchange protocol like TAXII, and FTP is not designed for this purpose.
- B. CVSS scores vulnerability severity; it is unrelated to sharing threat intelligence indicators.
- C. YARA is used for malware pattern matching/signatures, not structured threat intel exchange, and SMTP is email, not a sharing protocol.
STIX/TAXII
STIX is a standardized language for representing cyber threat intelligence; TAXII is the protocol used to exchange STIX data between organizations automatically.
- STIX = data format (JSON-based)
- TAXII = transport protocol (REST API-based)
- Enables automated, machine-to-machine threat intel sharing
Memory trick: STIX writes the letter, TAXII delivers the mail.