Question 1 of 25
What can be integrated with Cisco Threat Intelligence Director to provide information about security threats, which allows the SOC to proactively automate responses to those threats?
Show answer
How others answered
- B100%
Explanation
i would go with B here. Because the TID is used if you want to use external (not cisco provided) Security Information / Observables, in addition to what you get from cisco -> "The Cisco Threat Intelligence Director (TID) operationalizes threat intelligence data, helping you aggregate intelligence data, configure defensive actions, and analyze threats in your environment. This feature is intended to supplement other Firepower functionality, offering an additional line of defense against threats" https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/cisco_threat_intelligence_director__tid_.html and for AMP you dont need the TID. AMP(for Networks) comes with its own configuration o the FMC for example where you can define the cloud you want to use etc.
Adapted from community discussion by zeroC00L · 2022-04-02 · 2 community upvotes. Third-party contribution; reviewed by our quality filter, not independently verified.
Supporting references