
Palo Alto Networks Certified XSOAR Engineer
The Palo Alto Networks Certified XSOAR Engineer certification validates the skills required to deploy, configure, manage, integrate, and troubleshoot Cortex XSOAR in security operations environments. It is designed for experienced security operations engineers who build and maintain automation and orchestration solutions. Earning this credential demonstrates your ability to streamline SOC workflows and respond to threats faster.
721 practice questions · Updated 2026-07-30
5Domains
33Objectives
186Concepts
721Questions
XSOAR-ENGINEER Curriculum
Every domain, objective, and concept the XSOAR-ENGINEER exam measures.
- Authentication Methods
- Authorization Roles and Permissions
- Configuring Authentication
- Configuring Authorization
- User and Role Management
- Integration with External Identity Providers
- Best Practices for Authentication and Authorization
- Planning engine deployment
- Deploying engines
- Engine lifecycle management
- Dev/Prod Environment Planning
- Deployment Workflow Management
- Environment Synchronization
- Maintenance and Upgrade Planning
- Marketplace pack installation
- Pack version updates
- Pack dependencies and compatibility
- Pack lifecycle management
- Troubleshooting pack issues
- Integration Instance Configuration
- Integration Instance Troubleshooting
- Integration Health Monitoring
- Integration Testing and Validation
- System Maintenance Best Practices
- Troubleshooting Methodology
- Log Analysis and Monitoring
- Common Issue Identification
- Resolution and Recovery Procedures
- Incident Lifecycle Stages
- Indicator Lifecycle Stages
- Incident vs. Indicator Relationship
- Lifecycle Management in XSOAR
- Field Types and Properties
- Custom Field Creation
- Layout Design
- Layout Sections and Widgets
- Layout Assignment
- Field-to-Layout Mapping
- Layout Permissions and Visibility
- Classifier and Mapper Basics
- Classifier Configuration
- Mapper Configuration
- Classifier and Mapper Integration
- Incident creation methods overview
- Manual incident creation
- Incident creation via API
- Incident creation via integrations
- Incident creation from alerts
- Incident creation via playbooks
- Incident creation from email
- Incident creation from webhooks
- Incident creation from scheduled tasks
- Incident Preprocessing Functions
- Incident Postprocessing Functions
- Common Preprocessing Use Cases
- Common Postprocessing Use Cases
- Configuration and Implementation
- Incident Type Playbooks
- Playbook Execution Flow
- Layouts Configuration
- Layout Assignment
- SLA Definitions
- SLA Monitoring and Enforcement
- Integration of Playbooks, Layouts, and SLAs
- List types in XSOAR
- Creating lists
- Editing lists
- Deleting lists
- List permissions and access control
- Using lists in playbooks and automations
- List synchronization and versioning
- Best practices for list management
- Playbook Task Input Configuration
- Playbook Task Output Configuration
- Task Results and Execution Data
- Using Context Data in Inputs and Outputs
- Handling Task Output Errors and Edge Cases
- Context Data Structure
- Referencing Context Data
- Manipulating Context Data
- Managing Automation Workflow
- Identify playbook task types
- Describe regular tasks
- Describe conditional tasks
- Describe data collection tasks
- Describe playbook tasks
- Describe section header tasks
- Describe task looping and scheduling
- Sub-playbook Inputs
- Sub-playbook Outputs
- Looping Configuration
- Looping with Inputs and Outputs
- Filter Syntax
- Transformer Types
- Data Manipulation
- Chaining Filters and Transformers
- Error Handling
- Playbook Debugger Overview
- Debugger Interface Navigation
- Setting Breakpoints
- Stepping Through Execution
- Inspecting Task Inputs and Outputs
- Modifying Context Data
- Using the Debugger for Development
- Using the Debugger for Troubleshooting
- Debugging with Incident Data
- Handling Errors in Debug Mode
- Built-in commands
- Built-in scripts
- Distinguishing commands and scripts
- Automation script creation
- Applying automation scripts
- Script testing and debugging
- Script versioning and maintenance
- Job creation
- Job management
- Job scheduling
- Job execution and monitoring
- Incident States
- Incident Actions
- State Transitions
- Impact of Actions on States
- War Room Overview
- Accessing the War Room
- Viewing War Room Entries
- Adding War Room Notes
- Running Commands in the War Room
- Using War Room Tasks
- Collaborating in the War Room
- Filtering and Searching War Room Entries
- Exporting War Room Data
- Define incident relationships
- Identify relationship types
- Create incident relationships
- Use relationships for context
- Manage relationships
- Dashboard Configuration
- Report Configuration
- Widget Types and Data Sources
- Dashboard and Report Sharing
- Scheduling and Exporting Reports
- Threat Intelligence Feeds
- Threat Intelligence Indicators
- Threat Intelligence Enrichment
- Threat Intelligence Reputation
- Threat Intelligence Sharing
- Threat Intelligence Integration
- Threat Intelligence Automation
- Indicator Creation Methods Overview
- Manual Indicator Creation
- Bulk Indicator Import
- Indicator Creation via Playbooks
- Indicator Creation via API
- Indicator Enrichment and Deduplication
- Indicator Lifecycle and Validation
- Indicator Types
- Indicator Fields
- Indicator Creation Methods
- Indicator Enrichment
- Indicator Scoring and Reputation
- Indicator Expiration and Lifecycle
- Indicator Tagging and Classification
- Indicator Sharing and Export
- Indicator De-duplication and Merging
- Indicator Management Best Practices
- Indicator Relationship Types
- Relationship Directionality
- Relationship Strength and Confidence
- Using Relationships for Enrichment
- Visualizing Indicator Relationships
- Indicator Enrichment Sources
- Enrichment Process
- Source Reliability Assessment
- Reliability Scoring
- Impact of Source Reliability on Decisions
- Threat Intel Sharing Overview
- External Security Services Integration
- Threat Intel Feeds
- Sharing Mechanisms
- Data Formatting and Normalization
- Automation and Playbooks
- Security and Compliance Considerations
- Purpose of indicator exclusions list
- Configuration of indicator exclusions
- Management of indicator exclusions
- Impact of exclusions on threat intelligence
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for XSOAR-ENGINEER, so none is invented.