
Palo Alto NetworksCertified XSOAR Engineer
Domain 5Objective 1
5.1 Identify and Describe Threat Intelligence Features XSOAR-ENGINEER Practice Questions (Page 4)
Part of the Threat Intelligence Management domain, which accounts for 18% of the XSOAR-ENGINEER exam.
26questions here
6free pages
7concepts
18%of the exam
Questions 16–20
- 16
What is the primary purpose of threat intelligence enrichment in Cortex XSOAR?
Select an answer first - 17
An analyst is investigating an incident and wants to enrich a suspicious domain with data from VirusTotal and WHOIS. They want the enrichment results to be stored on the indicator for future reference. What should they do?
Select an answer first - 18
Which XSOAR feature is commonly used to perform automatic enrichment of indicators during incident handling?
Select an answer first - 19
A threat intelligence team needs to share a subset of indicators with a partner. The partner only wants indicators that are related to a specific campaign and have a confidence score above 70. The indicators are stored in XSOAR with custom fields for campaign and confidence. What is the most efficient way to export only the relevant indicators?
Select an answer first - 20
A threat intelligence team has curated a set of high-confidence indicators in XSOAR and wants to share them with a partner organization that uses a different threat intelligence platform. The partner can consume STIX 2.1. What is the most appropriate way to export the indicators?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XSOAR-ENGINEER” is a trademark of its owner, used for identification only.