Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium

A security operations center (SOC) is migrating its incident response playbooks to Cortex XSOAR. They have an existing proprietary threat intelligence feed that provides indicators of compromise (IOCs) via a custom HTTP endpoint. The SOC needs to integrate this feed into XSOAR for automatic fetching of new IOCs every 15 minutes. Which integration type is BEST suited for this requirement?

  1. ASIEM integration
  2. BFeed integration
  3. CCloud service integration
  4. DGeneric API integration
Show answer & explanation

Correct answer: B. Feed integration

A Feed integration is specifically designed in Cortex XSOAR for periodically fetching data (like IOCs) from external sources, making it the ideal choice for a custom threat intelligence feed that needs to be updated regularly.

Why the other options are wrong

  • A. SIEM integrations are designed for fetching security events and alerts from Security Information and Event Management systems, not general threat intelligence feeds.
  • C. Cloud service integrations are for interacting with specific cloud platforms (e.g., AWS, Azure), not a generic custom HTTP threat intelligence endpoint.
  • D. Generic API integrations are for general-purpose interaction with APIs, not specifically optimized for periodic feed ingestion.

Feed Integration Type

A specialized integration type in Cortex XSOAR designed for regularly fetching data (e.g., IOCs, threat intelligence) from external sources on a scheduled basis.

  • Optimized for periodic data ingestion.
  • Commonly used for threat intelligence feeds.
  • Supports various protocols like HTTP, TAXII.

Memory trick: Integration types match the data source and purpose.

More Integrations questions