Courseiva

XSOAR-Engineer · domain

Threat Intelligence Management

Practise Certified XSOAR Engineer (XSOAR-Engineer) Threat Intelligence Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

40 questions14 easy13 medium13 hard

Focused practice

Practice Threat Intelligence Management questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Threat Intelligence Management

Threat Intelligence Management questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Threat Intelligence Management exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Threat Intelligence Management questions (40)

Click any question to see the full explanation, or start a practice session above.

1

An analyst wants to generate a report summarizing all critical indicators ingested over the past week tagged with 'APT29'. Where can this report be created and scheduled?

Medium
2

When troubleshooting a feed integration that fails to parse incoming data, which TWO diagnostic steps should an administrator take? Choose 2 answers.

Hard
3

An enterprise uses Cortex XSOAR to synchronize indicators to multiple firewall enforcement points. A feed pushes indicators with a custom attribute. How can the administrator ensure this custom attribute is included in the exported TAXII/STIX bundle?

Hard
4

Which TWO considerations are critical when planning custom indicator mapping for a non-standard JSON threat feed? Choose 2 answers.

Hard
5

Where can an administrator view the status and execution logs of scheduled threat feed fetches in Cortex XSOAR?

Easy
6

Which indicator type should an administrator select when configuring a feed that supplies malicious URL strings?

Easy
7

A feed integration is pulling indicators successfully, but the correlation rules are not triggering when new incidents are created with matching observables. What is the most likely cause?

Hard
8

Where can an administrator view summary metrics regarding total indicators, breakdown by type, and top malicious sources in Cortex XSOAR?

Easy
9

An analyst observes that an indicator's score is fluctuating between malicious and benign because two different feeds report contradictory reputations. How can the administrator enforce that Feed A always takes precedence over Feed B?

Medium
10

Which TWO advanced configurations are required when setting up a TAXII 2.0/2.1 client feed in Cortex XSOAR? Choose 2 answers.

Hard
11

An analyst identifies a false positive indicator that is currently marking legitimate outbound traffic as malicious. What action should the analyst take to neutralize its effect globally in XSOAR?

Easy
12

Which THREE methods can be used to export threat indicators out of Cortex XSOAR to external systems? Choose 3 answers.

Medium
13

An administrator notices that duplicate indicators are being created from multiple feeds with slightly different formatting (e.g., lowercase vs uppercase domains). How does Cortex XSOAR handle indicator deduplication?

Medium
14

An analyst wants to bulk update the tags of 500 indicators selected from a Threat Intel query result. Which feature should be used?

Medium
15

When configuring a feed integration instance, the administrator selects 'Trust level' as 'Good'. How does this affect the indicator's calculated score when conflicting with a malicious feed?

Hard
16

A scheduled feed is failing with a certificate verification error because the feed source uses an internal self-signed SSL certificate. How can an administrator resolve this in Cortex XSOAR?

Medium
17

When setting up a new threat intelligence feed, what parameter determines how far back in time the integration pulls historical indicators upon initial run?

Easy
18

Which TWO actions can an administrator perform within the Cortex XSOAR Threat Intel workspace when managing indicators? Choose 2 answers.

Easy
19

Which TWO Cortex XSOAR features assist analysts in investigating indicators found in threat feeds? Choose 2 answers.

Easy
20

Which THREE parameters are typically required when configuring a generic REST API feed integration instance in Cortex XSOAR? Choose 3 answers.

Medium
21

Which TWO factors influence the final calculated reputation score of an indicator when multiple feeds provide conflicting data? Choose 2 answers.

Hard
22

Which THREE types of data can be ingested as threat intelligence indicators in Cortex XSOAR out-of-the-box? Choose 3 answers.

Medium
23

An organization wants to expire indicators automatically if they have not been seen in any incoming feeds for 90 days. Where is this expiration threshold configured?

Medium
24

An administrator wants to ensure that threat indicators received from a low-reputation feed do not automatically alter overall incident severities. Where is indicator-to-incident impact configured?

Medium
25

Which THREE configuration settings can be applied to manage indicator lifecycles in Cortex XSOAR? Choose 3 answers.

Medium
26

Which TWO attributes are mandatory when defining a custom indicator type in Cortex XSOAR? Choose 2 answers.

Easy
27

An analyst needs to quickly check whether an MD5 file hash exists across all active threat intel feeds without navigating through multiple menus. Where can this be performed?

Easy
28

An analyst wants to view the historical reputation changes of a specific malicious IP address over time. Which tab within the Indicator Details page provides this timeline?

Easy
29

An organization uses a custom threat feed that updates via an API requiring OAuth2 authentication with token rotation. How should the administrator configure this integration instance?

Hard
30

A custom threat intelligence feed integration is returning timeout errors during large data fetches. Which integration parameter should the administrator adjust to handle large payloads?

Hard
31

Which TWO details are typically visible within an individual Indicator Details view in Cortex XSOAR? Choose 2 answers.

Easy
32

When exporting indicators from Cortex XSOAR to an external SIEM using a TAXII server integration, the recipient reports missing custom fields. What configuration must be checked?

Hard
33

An administrator needs to temporarily disable a noisy threat intelligence feed without losing its configuration settings. What is the correct action?

Easy
34

An administrator needs to ingest a custom JSON threat feed that does not conform to standard out-of-the-box integrations. Which integration type should be built or configured to handle this custom structure?

Hard
35

A security analyst notices that indicators fetched from a specific OSINT feed are overriding higher-confidence internal indicators. Where should the administrator configure indicator scoring rules to resolve this?

Medium
36

An XSOAR administrator has integrated a new TAXII server feed, but indicators are not populating in the Threat Intel page. Which component must be verified first to ensure ingestion is functioning?

Easy
37

When writing a custom Python integration for a threat feed, which Demisto/XSOAR command is used to ingest fetched indicators into the platform database?

Hard
38

An analyst wants to manually add a single known malicious domain to the Threat Intel database. Which method is most direct?

Easy
39

An administrator needs to run a query in the Threat Intel workspace to find all active IP indicators with a 'Bad' reputation associated with a specific campaign tag. Which search syntax is correct?

Medium
40

An enterprise requires that all threat indicators ingested from external feeds be automatically enriched via VirusTotal before being marked as active. Where should this workflow logic be configured?

Hard

Frequently asked questions

What does the Threat Intelligence Management domain cover on the XSOAR-Engineer exam?
Threat Intelligence Management questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 40 Threat Intelligence Management questions in the XSOAR-Engineer question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Threat Intelligence Management questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
panw-xsoar-engineer PANW-XSOAR-ENGINEER threat intelligence management Practice Questions