How Do You Validate TID Feeds Are Downloaded and Used?
An administrator configures new threat intelligence sources and must validate that the feeds are being downloaded and that the intelligence is being used within the Cisco Secure Firewall system. Which action accomplishes the task?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests whether you can validate both halves of TID (feed downloaded and intelligence in use), and the trap is picking an option such as the access control policy or connection events that only demonstrates one half, or neither.
In Cisco Secure Firewall Management Center, the Threat Intelligence Director source status indicator is the practical way to confirm that newly configured threat intelligence sources were downloaded and published to sensors. This page explains why option B satisfies both halves of the validation task while the other options only prove enforcement, downloads, or policy enablement.
The most common wrong pick is D — checking the access control policy — because administrators assume that verifying the 'Enable Threat Intelligence Director' checkbox in Advanced Settings proves the intelligence is live, when it only shows the feature is turned on for the policy, not that the new sources actually downloaded indicators or were published to sensors; option A is the runner-up mistake, since it only shows enforcement after a flow already matches an observable.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
On the FMC Threat Intelligence Director Sources page, each configured feed carries a source status indicator that reports the feed's state — whether it was successfully retrieved, how many observables it contributed, and whether it has been published (pushed) to the managed Threat Defense devices. Cisco's own TID configuration and troubleshooting guide walks an administrator through exactly this verification path: confirm the source is populated, then confirm it is published so the observables are distributed to sensors, which can take up to 20 minutes or more. Because the task asks for both 'feeds are being downloaded' and 'the intelligence is being used,' the source status indicator is the single action that answers both questions at once. An unpublished, error-state, or zero-indicator feed is immediately visible there, which is precisely why B is the intended answer.Why the Other Options Are Wrong
Option A (connection security intelligence events) is tempting because TID observables eventually surface as Security Intelligence events, but those events only appear when live traffic matches a monitored or blocked observable — a quiet network would show nothing even when feeds are healthy, and it never proves the feeds downloaded. Option C (viewing threat intelligence observables) does verify that indicator content arrived in FMC, so it covers the download half but says nothing about whether that data was published and consumed by the devices. Option D (checking the access control policy) only confirms that the TID toggle is enabled in the policy's Advanced Settings; a policy with TID enabled can still sit on top of stale or never-published sources, so it cannot validate the sources the administrator just added.Community Comment Notes
As gwb pointed out, the question deliberately asks two things — are the feeds downloaded, and is the intelligence being used — and the status/indicator view is what answers the first requirement directly. Stevens0103 reached the same verdict, structuring the reasoning around the guide's steps, where "Under the Indicator tab, you can confirm if indicators were downloaded property from the configured sources" and the indicator details confirm what was ingested. jsomers cited the Cisco TID configuration and troubleshooting document as the basis for choosing B, and that document's verification workflow matches the source status indicator reasoning. LC1980 preferred D, arguing that you must verify the "Enable Threat Intelligence Director" checkbox under Advanced Settings of the access control policy to know the source is published to the FTD — but that checkbox only proves the feature is enabled on the policy, not that the new feeds downloaded or are being used.Official Reference
Exam Strategy
Separate the three states in any TID question: feature enabled in the access control policy, feed downloaded into FMC, and observables published/consumed by sensors. The option that reports source status covers the download-and-use pair, while policy screens and connection events only answer one narrow slice.
Frequently Asked Questions
Why isn't checking the access control policy enough to confirm TID feeds are working?
The Advanced Settings checkbox only shows TID is enabled on that policy. It does not confirm the new sources downloaded indicators or that they were published to the Threat Defense devices.
Where in FMC do I confirm TID indicators were actually downloaded?
On the Threat Intelligence Director Sources page, the source status indicator and indicator count show whether each configured feed was retrieved successfully and whether it has been published to sensors.