CompTIA Security+ (SY0-701)Security OperationsMedium

A security engineer is configuring a network device to block traffic from known malicious IP addresses and domains, as identified by various threat intelligence feeds. This device will automatically update its blocklists from these feeds and apply the rules in real-time. Which enterprise security tool is being configured?

  1. AFirewall with integrated threat intelligence
  2. BData Loss Prevention (DLP)
  3. CSecurity Orchestration, Automation, and Response (SOAR)
  4. DSecurity Information and Event Management (SIEM)
Show answer & explanation

Correct answer: A. Firewall with integrated threat intelligence

A firewall with integrated threat intelligence is designed to automatically ingest and apply threat intelligence feeds to block traffic from known malicious sources (IPs, domains) in real-time at the network perimeter. This functionality is often found in Next-Generation Firewalls (NGFWs).

Why the other options are wrong

  • B. DLP focuses on preventing sensitive data from leaving the organization, not blocking malicious inbound/outbound network traffic based on threat intelligence.
  • C. SOAR orchestrates and automates security tasks and workflows, but the device itself that performs the blocking based on threat intelligence is typically a firewall.
  • D. SIEM aggregates and analyzes logs but doesn't directly block network traffic based on threat intelligence feeds.

Firewall with Integrated Threat Intelligence

A network firewall that automatically consumes and applies external threat intelligence feeds to block traffic from known malicious IP addresses, domains, or other indicators of compromise.

  • Automates blocking of known threats.
  • Leverages external threat data.
  • Enhances network perimeter security in real-time.

Memory trick: A 'Firewall' with 'Intelligence' is like a smart 'Guard' at the gate, knowing who to block.

More Security Operations questions