Courseiva

XSIAM-Analyst · domain

Threat Intelligence Management And ASM

Practise Certified XSIAM Analyst (XSIAM-Analyst) Threat Intelligence Management And ASM practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

30 questions10 easy10 medium10 hard

Focused practice

Practice Threat Intelligence Management And ASM questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Threat Intelligence Management And ASM

Threat Intelligence Management And ASM questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Threat Intelligence Management And ASM exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Threat Intelligence Management And ASM questions (30)

Click any question to see the full explanation, or start a practice session above.

1

An analyst is investigating an incident where an internal host communicated with a known malicious domain. To verify when the threat intelligence indicator was first and last seen by XSIAM, where should the analyst look?

Medium
2

An analyst is reviewing threat intelligence indicators and notices a specific file hash is marked as 'Expired'. What does this status indicate in XSIAM?

Medium
3

When managing threat intelligence feeds in XSIAM, which THREE options are available for configuring feed synchronization intervals? (Choose three)

Medium
4

When reviewing Attack Surface Management (ASM) scan results in XSIAM, an administrator can classify discovered assets using various status designations. Which THREE statuses are standard asset classifications in ASM? (Choose three)

Hard
5

Which TWO actions can an analyst perform on a threat intelligence indicator directly from the XSIAM Threat Intelligence workspace? (Choose two)

Easy
6

What information does an indicator's 'TLP' (Traffic Light Protocol) designation provide in XSIAM?

Easy
7

What is the primary benefit of continuous Attack Surface Management (ASM) monitoring compared to periodic external vulnerability scans?

Easy
8

When configuring a Threat Intelligence feed using a custom REST API integration in XSIAM, the API requires a bearer token for authentication that expires every 60 minutes. How should this authentication be managed within the integration instance configuration?

Hard
9

When setting up a threat intelligence feed integration in XSIAM, what is the purpose of the 'Fetch Indicators' toggle?

Easy
10

An organization's security policy requires that any threat intelligence indicator originating from an untrusted open-source feed must not automatically generate high-severity blocking alerts. How can this policy be enforced in XSIAM?

Hard
11

You are configuring Attack Surface Management in XSIAM to monitor brand infringement and typosquatting domains. Which ASM configuration feature enables this capability?

Hard
12

An organization wants to configure custom threat intelligence scoring in XSIAM. Which THREE factors can influence the composite threat score of an indicator within the platform? (Choose three)

Hard
13

Which type of indicators can be ingested into XSIAM's Threat Intelligence module?

Easy
14

An analyst is configuring a new threat intelligence feed in XSIAM to ingest Indicators of Compromise (IoCs). Which integration mechanism should be used to pull indicators natively from an external TAXII 2.1 server?

Easy
15

An analyst wants to suppress a specific threat intelligence indicator that has been identified as a false positive across all correlation rules in XSIAM. What is the correct procedure?

Medium
16

Which TWO protocols or formats are natively supported for importing threat intelligence feeds into Cortex XSIAM? (Choose two)

Easy
17

What is the purpose of tagging threat intelligence indicators in XSIAM?

Easy
18

An administrator needs to ensure that custom threat intelligence indicators ingested via a CSV file maintain a specific custom severity rating of 'Critical' regardless of external provider scores. How should this be configured in XSIAM?

Hard
19

An administrator is setting up Attack Surface Management (ASM) discovery scopes in XSIAM. Which THREE types of seed assets can be provided to initiate external discovery? (Choose three)

Hard
20

An analyst is investigating an ASM finding regarding an exposed service on an external asset. Which THREE details are typically provided within the ASM finding record in XSIAM? (Choose three)

Hard
21

Which TWO methods can an analyst use to investigate matches between internal network telemetry and threat intelligence indicators in XSIAM? (Choose two)

Medium
22

An ASM discovery run identifies a rogue cloud storage bucket publicly exposed to the internet. How does XSIAM's ASM module typically discover this asset without requiring internal cloud credentials?

Hard
23

Where in the XSIAM user interface should an analyst navigate to review discovered external assets, shadow IT, and exposed services identified by Attack Surface Management?

Easy
24

You are configuring correlation rules in XSIAM to trigger an incident when internal telemetry matches indicators from a high-confidence threat feed. How do you ensure that indicators from low-confidence feeds are filtered out of this specific rule?

Hard
25

What is the primary function of Attack Surface Management (ASM) within Cortex XSIAM?

Easy
26

When configuring a new threat intelligence feed integration in Cortex XSIAM, which TWO configuration parameters are typically required for successful API-based ingestion? (Choose two)

Medium
27

An organization wants to integrate a proprietary threat intelligence feed that uses a non-standard JSON format. What tool or method should be used within XSIAM to ingest and parse this feed correctly?

Medium
28

An XSIAM analyst notices that a high-fidelity threat intelligence indicator is generating low-priority alerts because its default expiration time is set too short. Where can the indicator expiration settings be adjusted?

Medium
29

You are troubleshooting an Attack Surface Management (ASM) scan in XSIAM where external IP ranges belonging to a newly acquired subsidiary are not showing up in the asset inventory. What is the most likely reason for this discrepancy?

Medium
30

An ASM scan in XSIAM flags an external web server as having an outdated SSL/TLS certificate. Where can an analyst view the detailed finding context and remediation recommendations for this exposed asset?

Medium

Frequently asked questions

What does the Threat Intelligence Management And ASM domain cover on the XSIAM-Analyst exam?
Threat Intelligence Management And ASM questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 30 Threat Intelligence Management And ASM questions in the XSIAM-Analyst question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Threat Intelligence Management And ASM questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
panw-xsiam-analyst PANW-XSIAM-ANALYST threat intelligence management and asm Practice Questions