How Do You Validate TID Feeds Are Downloaded and Used?

Implement Threat Intelligence Director for third-party security intelligence feeds
Answer Correct answer: B — use the Threat Intelligence Director source status indicator in FMC to confirm the feeds were downloaded and published to sensors so the intelligence is being used.

An administrator configures new threat intelligence sources and must validate that the feeds are being downloaded and that the intelligence is being used within the Cisco Secure Firewall system. Which action accomplishes the task?

  1. Look at the connection security intelligence events
  2. Use the source status indicator to validate the usage Correct Answer
  3. View the threat intelligence observables to see the downloaded data
  4. Look at the access control policy to validate that the intelligence is being used

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests whether you can validate both halves of TID (feed downloaded and intelligence in use), and the trap is picking an option such as the access control policy or connection events that only demonstrates one half, or neither.

In Cisco Secure Firewall Management Center, the Threat Intelligence Director source status indicator is the practical way to confirm that newly configured threat intelligence sources were downloaded and published to sensors. This page explains why option B satisfies both halves of the validation task while the other options only prove enforcement, downloads, or policy enablement.

The most common wrong pick is D — checking the access control policy — because administrators assume that verifying the 'Enable Threat Intelligence Director' checkbox in Advanced Settings proves the intelligence is live, when it only shows the feature is turned on for the policy, not that the new sources actually downloaded indicators or were published to sensors; option A is the runner-up mistake, since it only shows enforcement after a flow already matches an observable.

Community Discussion (4 comments)

gwb 👍 3
My answer is "A". B seems right. Q is asking two things 1. are being downloaded? 2. is being used? According to below explanation, this met #1 requirement. By default, all sources are published, this means that they are pushed to sensors. This process can take up to 20 minutes or more. Step 3. Under the Indicator tab, you can confirm if indicators were downloaded property from the configured sources: However, to confirm that is being used as well, we need to verify from the live data which is method 2. So my answer is A Method 1. To verify if TID acted on the traffic, you need to navigate to the Incidents tab. Method 2. The incidents can be found under the Security Intelligence Events tab under a TID tag. Method 3. You can confirm if configured sources (feeds) are present on the FMC and a sensor. To do that, you can navigate to these locations on the CLI:
Stevens0103 👍 3 Selected: B
Two requirements. First, validate the feeds are being downloaded: "Step 3. Under the Indicator tab, you can confirm if indicators were downloaded property from the configured sources:" Second, validate that the intelligence is being used: "Step 4. Once you select the name of an indicator you can see more details about it. Indicator Details NAME ZeuS Tracker (offline)| 13d.pp.ru/global/config.jp (2017-08-16) | This domain has been identified as malicious by zeustracker.abuse.ch DESCRIPTION This domain 13d.pp.ru has been identified as malicious by zeustracker.abuse.ch. For more detailed infomation about this indicator go to [CAUTION !! Read-URL-Before-Click] [https://zeustracker.abuse.ch/monitor.php?host=13d.pp.ru]." https://www.cisco.com/c/en/us/support/docs/storage-networking/security/214859-configure-and-troubleshoot-cisco-threat.html
jsomers 👍 1
https://www.cisco.com/c/en/us/support/docs/storage-networking/security/214859-configure-and-troubleshoot-cisco-threat.html Option - B
LC1980 👍 1
I prefer option D, answer says that user has already configured a source, so to check that source will be published on FTD device you need to Verify that the Enable Threat Intelligence Director check box is checked in Advanced Settings of the access control policy.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

On the FMC Threat Intelligence Director Sources page, each configured feed carries a source status indicator that reports the feed's state — whether it was successfully retrieved, how many observables it contributed, and whether it has been published (pushed) to the managed Threat Defense devices. Cisco's own TID configuration and troubleshooting guide walks an administrator through exactly this verification path: confirm the source is populated, then confirm it is published so the observables are distributed to sensors, which can take up to 20 minutes or more. Because the task asks for both 'feeds are being downloaded' and 'the intelligence is being used,' the source status indicator is the single action that answers both questions at once. An unpublished, error-state, or zero-indicator feed is immediately visible there, which is precisely why B is the intended answer.

Why the Other Options Are Wrong

Option A (connection security intelligence events) is tempting because TID observables eventually surface as Security Intelligence events, but those events only appear when live traffic matches a monitored or blocked observable — a quiet network would show nothing even when feeds are healthy, and it never proves the feeds downloaded. Option C (viewing threat intelligence observables) does verify that indicator content arrived in FMC, so it covers the download half but says nothing about whether that data was published and consumed by the devices. Option D (checking the access control policy) only confirms that the TID toggle is enabled in the policy's Advanced Settings; a policy with TID enabled can still sit on top of stale or never-published sources, so it cannot validate the sources the administrator just added.

Community Comment Notes

As gwb pointed out, the question deliberately asks two things — are the feeds downloaded, and is the intelligence being used — and the status/indicator view is what answers the first requirement directly. Stevens0103 reached the same verdict, structuring the reasoning around the guide's steps, where "Under the Indicator tab, you can confirm if indicators were downloaded property from the configured sources" and the indicator details confirm what was ingested. jsomers cited the Cisco TID configuration and troubleshooting document as the basis for choosing B, and that document's verification workflow matches the source status indicator reasoning. LC1980 preferred D, arguing that you must verify the "Enable Threat Intelligence Director" checkbox under Advanced Settings of the access control policy to know the source is published to the FTD — but that checkbox only proves the feature is enabled on the policy, not that the new feeds downloaded or are being used.

Official Reference

Exam Strategy

Separate the three states in any TID question: feature enabled in the access control policy, feed downloaded into FMC, and observables published/consumed by sensors. The option that reports source status covers the download-and-use pair, while policy screens and connection events only answer one narrow slice.

Frequently Asked Questions

Why isn't checking the access control policy enough to confirm TID feeds are working?

The Advanced Settings checkbox only shows TID is enabled on that policy. It does not confirm the new sources downloaded indicators or that they were published to the Threat Defense devices.

Where in FMC do I confirm TID indicators were actually downloaded?

On the Threat Intelligence Director Sources page, the source status indicator and indicator count show whether each configured feed was retrieved successfully and whether it has been published to sensors.

Related Analysis

← Back to 300-710 Study Guide