Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsEasy
A security operations team is onboarding a new threat intelligence feed into Cortex XSOAR. The feed provides indicators of compromise (IOCs) such as malicious IP addresses and URLs. The team wants these IOCs to be automatically ingested and updated regularly to enrich incidents and trigger playbooks. Which integration type is best suited for this requirement?
- AAction-Only Integration
- BGeneric API Integration
- CFeed Integration
- DIncident Fetch Integration
Show answer & explanationAnswer & explanation
Correct answer: C. Feed Integration
Feed integrations are specifically designed to ingest and update threat intelligence indicators (IOCs) from external sources at regular intervals, making them ideal for enriching incidents and driving automated responses.
Why the other options are wrong
- A. An Action-Only Integration performs specific actions but does not inherently manage or update a continuous stream of indicators.
- B. A Generic API Integration can retrieve data but lacks the specialized indicator management capabilities of a Feed integration.
- D. An Incident Fetch Integration is designed to pull incidents or alerts, not specifically to manage and update threat intelligence indicators.
Feed Integration Type
A Feed integration in Cortex XSOAR is designed to ingest and continuously update threat intelligence indicators (IOCs) from external sources.
- Specialized for threat intelligence.
- Automatically updates indicators.
- Used for enrichment and playbook triggering.
Memory trick: Different integrations have different 'jobs' in XSOAR.