
Palo Alto NetworksCertified XSOAR Engineer
Domain 5Objective 5
5.5 Demonstrate Knowledge of Indicator Enrichment and Source Reliability XSOAR-ENGINEER Practice Questions (Page 3)
Part of the Threat Intelligence Management domain, which accounts for 18% of the XSOAR-ENGINEER exam.
21questions here
5free pages
5concepts
18%of the exam
Questions 11–15
- 11
What is the primary purpose of using multiple enrichment sources for an indicator?
Select an answer first - 12
An XSOAR playbook enriches a file hash and receives a 'malicious' verdict from a high-reliability source and a 'benign' verdict from a low-reliability source. The playbook is configured to automatically block files with high confidence. What should the playbook do?
Select an answer first - 13
A threat intelligence team is evaluating two enrichment sources. Source A has been highly accurate for two years but has a 24-hour delay in updates. Source B has been accurate for only three months but provides real-time updates. The team needs to enrich indicators for a zero-day campaign that is evolving rapidly. Which source should the team rely on more heavily?
Select an answer first - 14
In the enrichment process, what is the purpose of aggregating results from multiple sources?
Select an answer first - 15
A threat intelligence team is evaluating two enrichment sources for IP reputation. Source A has a 99% accuracy rate but updates its database only once a week. Source B has a 95% accuracy rate but updates in near real-time. An analyst needs to enrich a fast-spreading phishing campaign indicator. Which source should the analyst prioritize?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XSOAR-ENGINEER” is a trademark of its owner, used for identification only.