Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsEasy

A security operations center (SOC) is onboarding a new threat intelligence feed into Cortex XSOAR. The feed provides indicators in a custom JSON format via an HTTP endpoint. The SOC wants to automatically ingest these indicators, enrich them, and use them to update blocking lists. Which type of integration is BEST suited for this scenario?

  1. ATicketing Integration
  2. BGeneric API Integration
  3. CBidirectional Integration
  4. DFeed Integration
Show answer & explanation

Correct answer: D. Feed Integration

Feed Integrations in Cortex XSOAR are specifically designed for ingesting threat intelligence indicators from external sources. They provide a standardized structure and mechanisms for processing, mapping, and managing indicators, making them ideal for this scenario.

Why the other options are wrong

  • A. Ticketing integrations are for incident management systems, not threat intelligence feeds.
  • B. A generic API integration could technically fetch data, but a feed integration provides the specific framework and features for TI consumption.
  • C. Bidirectional integrations imply interaction both ways (e.g., XSOAR creating incidents, external system updating them), which is not the primary focus here.

Feed Integration Type

Cortex XSOAR Feed Integrations are specialized integration types designed for ingesting threat intelligence indicators from external sources, providing built-in mechanisms for indicator processing and management.

  • Purpose-built for threat intelligence.
  • Standardized indicator ingestion.
  • Supports various feed formats (e.g., JSON, CSV, STIX).

Memory trick: When 'feeding' indicators, use the 'feed' integration.

More Integrations questions