
Palo Alto NetworksCertified XSOAR Engineer
Domain 5Objective 4
5.4 Explain Indicator Relationships XSOAR-ENGINEER Practice Questions (Page 1)
Part of the Threat Intelligence Management domain, which accounts for 18% of the XSOAR-ENGINEER exam.
18questions here
4free pages
5concepts
18%of the exam
Questions 1–5
- 1
An analyst observes two distinct IP addresses that are both used as C2 servers for the same malware family but have no direct interaction with each other. Which relationship type best describes the connection between these two IP addresses?
Select an answer first - 2
A threat intel platform shows a relationship between an IP address and a domain. The relationship is based on a single passive DNS record that has not been updated in 18 months. An analyst needs to assess the confidence of this relationship. What is the most appropriate confidence level?
Select an answer first - 3
An analyst is investigating a newly discovered domain that has a relationship to a known malicious IP. The relationship is marked as 'peer' with high confidence. How should the analyst use this relationship for enrichment?
Select an answer first - 4
An analyst is investigating a domain that has a relationship with a known phishing kit. How can this relationship enrich the analyst's understanding of the domain?
Select an answer first - 5
In a threat intelligence graph, a malware hash has an incoming edge labeled 'dropped by' from a document hash. What is the directionality of this relationship?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XSOAR-ENGINEER” is a trademark of its owner, used for identification only.