Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium
A security operations center (SOC) is migrating its incident response playbooks to Cortex XSOAR. They have an existing proprietary threat intelligence feed that provides indicators of compromise (IOCs) via a custom HTTP endpoint. The SOC needs to integrate this feed into XSOAR for automatic fetching of new IOCs every 15 minutes. Which integration type is BEST suited for this requirement?
- ASIEM integration
- BFeed integration
- CCloud service integration
- DGeneric API integration
Show answer & explanationAnswer & explanation
Correct answer: B. Feed integration
A Feed integration is specifically designed in Cortex XSOAR for periodically fetching data (like IOCs) from external sources, making it the ideal choice for a custom threat intelligence feed that needs to be updated regularly.
Why the other options are wrong
- A. SIEM integrations are designed for fetching security events and alerts from Security Information and Event Management systems, not general threat intelligence feeds.
- C. Cloud service integrations are for interacting with specific cloud platforms (e.g., AWS, Azure), not a generic custom HTTP threat intelligence endpoint.
- D. Generic API integrations are for general-purpose interaction with APIs, not specifically optimized for periodic feed ingestion.
Feed Integration Type
A specialized integration type in Cortex XSOAR designed for regularly fetching data (e.g., IOCs, threat intelligence) from external sources on a scheduled basis.
- Optimized for periodic data ingestion.
- Commonly used for threat intelligence feeds.
- Supports various protocols like HTTP, TAXII.
Memory trick: Integration types match the data source and purpose.