Courseiva

XDR-Engineer · topic practice

Ingestion And Automation practice questions

Practise Certified XDR Engineer (XDR-Engineer) Ingestion And Automation practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Ingestion And Automation

What the exam tests

What to know about Ingestion And Automation

Ingestion And Automation questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Ingestion And Automation exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Ingestion And Automation questions

20 questions · select your answer, then reveal the explanation

An administrator has configured a Cortex XDR data ingestion rule for a custom log source, but fields are appearing under the 'general_fields' object rather than their designated mapped schema columns. What is the most likely reason for this parsing failure?

An administrator is deploying a Broker VM in a DMZ to ingest logs via API from an external cloud provider. The Broker VM fails to authenticate with the external API endpoint due to self-signed certificate validation errors. What is the correct procedure to resolve this on the Broker VM?

A security analyst needs to ingest custom JSON-formatted security logs from an in-house application into Cortex XDR. Where should the administrator define the custom log mapping to ensure fields are parsed correctly under the generic log profile schema?

Question 4mediummultiple choice
Read the full Ansible explanation →

An administrator is building a playbook in Cortex XDR incident response automation. The playbook needs to isolate an endpoint only if a specific malicious process hash is confirmed by a secondary sandbox analysis task. Which element should be used in the playbook workflow to enforce this conditional logic?

Which menu path in the Cortex XDR management console should an administrator navigate to view the overall health, status, and log forwarding statistics of deployed Broker VMs?

When configuring an integration instance in Cortex XSOAR (or Cortex XDR Automation) for a third-party threat intelligence feed, what is the primary purpose of the instance name?

An administrator is troubleshooting a Cortex XDR syslog integration where logs from a high-throughput network device are being dropped or delayed. The Broker VM resource utilization for CPU and memory is normal. Which underlying collector configuration setting should be adjusted to handle the high burst rate?

An organization requires that logs ingested via the Cortex XDR Syslog Collector be secured using TLS encryption (Syslog-over-TLS). What must the administrator configure on the Broker VM to support this requirement?

An administrator is configuring a Syslog Collector agent on Cortex XDR to ingest logs from a third-party firewall. Which log collection protocol and transport layer combination is natively supported by the Cortex XDR Collector for receiving unencrypted syslog messages?

An administrator needs to write a custom automation script in Cortex XSOAR to query the Cortex XDR API for all endpoints that have not checked in within the last 7 days. Which API endpoint and filtering mechanism should the script use?

When setting up data forwarding from Cortex XDR to a third-party SIEM using the Cortex XDR Data Forwarder, which protocol is commonly used to stream the logs?

An administrator needs to ingest CEF (Common Event Format) logs from a third-party security device using the Broker VM. Which collector type must be enabled on the Broker VM configuration page in Cortex XDR?

Question 13hardmultiple choice
Read the full Ansible explanation →

An automation playbook in Cortex XSOAR requires parsing a raw email message payload received in an incident. Which built-in automation command or integration should the playbook use to extract indicators of compromise (IOCs) such as URLs, IPs, and file hashes from the email body?

An administrator has configured a new AWS CloudTrail integration via Broker VM to ingest cloud logs into Cortex XDR. However, no logs are appearing in the XDR database. Upon reviewing the Broker VM logs, the administrator notices an 'AccessDenied' error from AWS. What is the most likely root cause?

Question 15easymultiple choice
Read the full Ansible explanation →

Which role is required within Cortex XDR for a user to configure API keys, data integration settings, and automation playbooks?

Question 16hardmultiple choice
Read the full Ansible explanation →

An automation playbook in Cortex XSOAR needs to execute a custom Python script that interacts with an internal legacy database not covered by existing Marketplace integrations. Which component should the administrator use to securely run this custom script?

Where in the Cortex XDR web interface can an administrator generate API keys (API Key and Incident ID / Key) required for external integrations and scripts to authenticate with the Cortex XDR API?

What is the primary function of the Cortex XDR 'Content Pack' in Marketplace?

Question 19hardmultiple choice
Review the full routing breakdown →

An enterprise environment uses a forward proxy for all outbound internet traffic. The Broker VM deployed in the internal network cannot reach external cloud APIs for threat intelligence enrichment. How should the administrator configure the Broker VM to route traffic through the forward proxy?

An administrator has deployed a Broker VM and enabled the Active Directory (AD) collector to ingest user and group mapping data. The connection test fails with a 'Kerberos Authentication Failed' error. What is the most likely cause of this failure?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Ingestion And Automation sessions

Start a Ingestion And Automation only practice session

Every question in these sessions is drawn from the Ingestion And Automation domain — nothing else.

Related practice questions

Related XDR-Engineer topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the XDR-Engineer exam test about Ingestion And Automation?
Ingestion And Automation questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Ingestion And Automation questions in a focused session?
Yes — the session launcher on this page draws every question from the Ingestion And Automation domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other XDR-Engineer topics?
Use the topic links above to move to related areas, or go back to the XDR-Engineer question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the XDR-Engineer exam covers. They are not copied from any real exam or dump site.