Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesHard
A large enterprise is facing increasing cyber threats and needs to improve its ability to predict and prevent attacks, rather than merely react to them. The cybersecurity architect is evaluating strategies to enhance security operations by leveraging external intelligence. Which strategy would be most effective for proactive threat intelligence integration and operationalization?
- AImplementing a Threat Intelligence Platform (TIP) that aggregates multiple commercial and open-source feeds, normalizes data, and integrates with SIEM, SOAR, and endpoint security solutions for automated correlation and enforcement.
- BSubscribing to a free public threat intelligence feed and manually updating firewall rules.
- CRelying on internal security team's ad-hoc research for threat intelligence.
- DMonitoring industry news and forums for reports of new vulnerabilities.
Show answer & explanationAnswer & explanation
Correct answer: A. Implementing a Threat Intelligence Platform (TIP) that aggregates multiple commercial and open-source feeds, normalizes data, and integrates with SIEM, SOAR, and endpoint security solutions for automated correlation and enforcement.
A TIP that aggregates, normalizes, and integrates threat intelligence with existing security tools enables automated correlation, proactive detection, and rapid enforcement of defenses, moving beyond reactive measures to predictive and preventive security operations.
Why the other options are wrong
- B. Free public feeds are often generic, and manual updates are slow and prone to error, making this approach ineffective for proactive defense against sophisticated threats.
- C. Ad-hoc internal research is insufficient to keep pace with the volume and sophistication of modern threats, leading to significant intelligence gaps.
- D. Monitoring news and forums provides awareness but lacks the structured, actionable, and automated integration needed to operationalize threat intelligence for proactive defense.
Threat Intelligence Platform (TIP)
A software solution that aggregates, processes, and disseminates threat intelligence from various sources, making it actionable for security operations.
- Normalizes and enriches threat data from multiple feeds.
- Integrates with SIEM, SOAR, firewalls, and other security controls.
- Enables proactive defense and automated incident response.
Memory trick: TIP Feeds Proactive Security Operations