Practice XDR-Engineer Ingestion And Automation questions with full explanations on every answer.
Start practicing
Ingestion And Automation — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
An administrator is deploying a Broker VM in a DMZ to ingest logs via API from an external cloud provider. The Broker VM fails to authenticate with the external API endpoint due to self-signed certificate validation errors. What is the correct procedure to resolve this on the Broker VM?
2A security analyst needs to ingest custom JSON-formatted security logs from an in-house application into Cortex XDR. Where should the administrator define the custom log mapping to ensure fields are parsed correctly under the generic log profile schema?
3An administrator is building a playbook in Cortex XDR incident response automation. The playbook needs to isolate an endpoint only if a specific malicious process hash is confirmed by a secondary sandbox analysis task. Which element should be used in the playbook workflow to enforce this conditional logic?
4Which menu path in the Cortex XDR management console should an administrator navigate to view the overall health, status, and log forwarding statistics of deployed Broker VMs?
5When configuring an integration instance in Cortex XSOAR (or Cortex XDR Automation) for a third-party threat intelligence feed, what is the primary purpose of the instance name?
6An administrator is troubleshooting a Cortex XDR syslog integration where logs from a high-throughput network device are being dropped or delayed. The Broker VM resource utilization for CPU and memory is normal. Which underlying collector configuration setting should be adjusted to handle the high burst rate?
7An organization requires that logs ingested via the Cortex XDR Syslog Collector be secured using TLS encryption (Syslog-over-TLS). What must the administrator configure on the Broker VM to support this requirement?
8An administrator is configuring a Syslog Collector agent on Cortex XDR to ingest logs from a third-party firewall. Which log collection protocol and transport layer combination is natively supported by the Cortex XDR Collector for receiving unencrypted syslog messages?
9An administrator needs to write a custom automation script in Cortex XSOAR to query the Cortex XDR API for all endpoints that have not checked in within the last 7 days. Which API endpoint and filtering mechanism should the script use?
10When setting up data forwarding from Cortex XDR to a third-party SIEM using the Cortex XDR Data Forwarder, which protocol is commonly used to stream the logs?
11An administrator needs to ingest CEF (Common Event Format) logs from a third-party security device using the Broker VM. Which collector type must be enabled on the Broker VM configuration page in Cortex XDR?
12An automation playbook in Cortex XSOAR requires parsing a raw email message payload received in an incident. Which built-in automation command or integration should the playbook use to extract indicators of compromise (IOCs) such as URLs, IPs, and file hashes from the email body?
13An administrator has configured a new AWS CloudTrail integration via Broker VM to ingest cloud logs into Cortex XDR. However, no logs are appearing in the XDR database. Upon reviewing the Broker VM logs, the administrator notices an 'AccessDenied' error from AWS. What is the most likely root cause?
14Which role is required within Cortex XDR for a user to configure API keys, data integration settings, and automation playbooks?
15An automation playbook in Cortex XSOAR needs to execute a custom Python script that interacts with an internal legacy database not covered by existing Marketplace integrations. Which component should the administrator use to securely run this custom script?
16Where in the Cortex XDR web interface can an administrator generate API keys (API Key and Incident ID / Key) required for external integrations and scripts to authenticate with the Cortex XDR API?
17What is the primary function of the Cortex XDR 'Content Pack' in Marketplace?
18An enterprise environment uses a forward proxy for all outbound internet traffic. The Broker VM deployed in the internal network cannot reach external cloud APIs for threat intelligence enrichment. How should the administrator configure the Broker VM to route traffic through the forward proxy?
19An administrator has deployed a Broker VM and enabled the Active Directory (AD) collector to ingest user and group mapping data. The connection test fails with a 'Kerberos Authentication Failed' error. What is the most likely cause of this failure?
20When testing a newly configured API integration instance in Cortex XSOAR, what is the standard action used to verify connectivity and authentication credentials?
21An administrator is configuring automated incident enrichment in Cortex XDR. Whenever a new malware incident is generated, the system should automatically query VirusTotal using an integration. Where should this automated workflow be built and attached?
22An enterprise security team wants to ingest NetFlow records from core routers into Cortex XDR. Which component and collector combination supports NetFlow/IPFIX ingestion?
23An administrator is configuring data forwarding filters in Cortex XDR to send specific severity alerts to a SIEM. The requirement is to forward all 'High' and 'Critical' severity alerts while excluding 'Low' and 'Medium' alerts. Where is this filter configured?
24An administrator is troubleshooting an API rate-limiting error (HTTP 429 Too Many Requests) occurring in a custom Cortex XSOAR automation playbook that queries an external threat intel API. How should the integration or playbook be modified to handle this gracefully?
25What is the primary purpose of using a Broker VM in a Cortex XDR deployment architecture?
26An administrator needs to ingest Office 365 audit logs into Cortex XDR. Which integration method is officially supported and recommended by Palo Alto Networks for this data source?
27Which TWO of the following data sources can be natively onboarded and collected using a Cortex XDR Broker VM? (Choose two)
28An administrator is configuring a new integration in Cortex XSOAR and needs to ensure secure credential handling. Which TWO practices are recommended when managing API keys and secrets? (Choose two)
29Which TWO actions can be performed directly within the Cortex XDR Data Integration management interface? (Choose two)
30When troubleshooting a failing Cortex XDR API query or automation script, which TWO logs or diagnostic tools should an administrator examine to diagnose the root cause? (Choose two)
31Which TWO authentication methods are commonly supported when configuring API integrations in Cortex XSOAR? (Choose two)
32An administrator is designing an automated incident response playbook in Cortex XSOAR. Which TWO core concepts are essential for passing data between playbook tasks? (Choose two)
33An organization requires high availability and load balancing for their Broker VM log ingestion tier. Which TWO architectural considerations or configurations support this requirement? (Choose two)
34Which TWO tasks can an automation playbook in Cortex XDR / XSOAR execute automatically upon detecting a confirmed threat? (Choose two)
35When configuring advanced data forwarding filters in Cortex XDR, which TWO criteria parameters can an administrator use to precisely target specific log types or endpoints? (Choose two)
36An administrator is setting up automated alert ingestion from a third-party SIEM into Cortex XSOAR. Which TWO integration methods or components are typically used to achieve this? (Choose two)
37An administrator needs to troubleshoot an AWS S3 bucket integration via Broker VM where logs are failing to ingest. Which TWO diagnostic steps should be taken? (Choose two)
38An administrator is configuring a new Syslog data collector in Cortex XDR to ingest logs from a third-party firewall. The logs are arriving at the Cortex XDR Collector, but they are not appearing in the Query Builder. Which step should the administrator perform to resolve this issue?
39An administrator is writing a custom Python automation script within a Cortex XSOAR integration. Which TWO standard practices should be followed to ensure proper execution and error handling within the platform? (Choose two)
40An XDR administrator needs to forward Cortex XDR alerts to an external SIEM. Which integration mechanism should be configured in the Cortex XDR management console under Data Collection?
41An automation engineer is building a Cortex XSOAR playbook that is triggered by a Cortex XDR incident. The playbook needs to fetch all associated endpoint artifacts using the Cortex XDR integration. Which parameter is required in the command execution to ensure all relevant forensics files are retrieved?
42When configuring the Cortex XDR API to ingest custom threat intelligence feeds, which authentication header and format must be used for the HTTP POST request to ensure successful ingestion?
43An administrator has deployed a Broker VM to act as a syslog collector and agent installer. During the configuration of the Broker VM in the Cortex XDR console, the status remains 'Disconnected'. What is the most likely cause of this issue?
44Where in the Cortex XDR management console can an administrator review the status and health of all connected data collectors, such as Broker VMs and agent collectors?
45An administrator is configuring the Cortex XDR API integration for automated incident management and data ingestion. Which TWO actions must be performed in the Cortex XDR management console to properly set up API access? (Choose two)
46An administrator wants to create a BIOC (Behavioral Indicator of Compromise) rule in Cortex XDR that triggers an alert whenever a PowerShell script attempts to download and execute a payload from an external IP address. Which data source must be enabled and properly ingested for this rule to function effectively?
47An organization is onboarding a new cloud environment into Cortex XDR. Which THREE mechanisms or components can be utilized to ingest cloud audit logs and telemetry data into Cortex XDR? (Choose three)
48When setting up automated alert response actions using Cortex XDR built-in response actions or XSOAR integrations, which THREE actions can be automatically initiated directly against an endpoint agent? (Choose three)
The Ingestion And Automation domain covers the key concepts tested in this area of the XDR-Engineer exam blueprint published by Palo Alto Networks. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all XDR-Engineer domains — no account required.
The Courseiva XDR-Engineer question bank contains 48 questions in the Ingestion And Automation domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Ingestion And Automation domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included