You Can Pass This Exam For Free
Choose Your Study Path
You have general security operations experience but have not worked with Cortex XSIAM or XSOAR. You need to learn the platform from scratch.
Exam Overview
Format
50-60 questions, 90 minutes. Multiple-choice, matching, and ordering question formats. Scenario-based questions are heavily emphasized.
Scoring
Scaled score 300-1000. Passing: 860. The high passing threshold (86%) reflects the specialist-level difficulty. No penalty for wrong answers.
Domains & Weights
- Planning and Installation22%
- Integration and Automation30%
- Content Optimization24%
- Maintenance and Troubleshooting24%
Registration
$250 USD. Available at Pearson VUE testing centers only (in-person). Online remote proctoring is no longer available. Exam fee is $250 USD. Certification is valid for 2 years.
Topic Priority Table
Not all topics are tested equally. Focus your study time on Tier 1 first, then Tier 2. Tier 3 topics rarely appear — just recognize what they do.
Planning and Installation
This domain covers evaluating deployment requirements, designing the XSIAM architecture, deploying Broker VMs and agents, and configuring the initial platform setup. You must understand infrastructure prerequisites, network requirements, data source planning, and the deployment lifecycle from evaluation through go-live.
Key Topics
Must-Know Concepts
- XSIAM cloud-native architecture: how the Cortex Data Lake, analytics engine, and automation engine work together as a unified platform
- Broker VM deployment: hardware requirements, supported hypervisors, network configuration, FQDN setup, clustering for high availability, and proxy configuration
- Cortex XDR agent deployment: supported operating systems (Windows, macOS, Linux), agent types, installation methods, and agent settings profiles
- Data source evaluation: identifying what data sources need to be ingested, mapping them to XDM schemas, and planning ingestion methods (syslog, API, agent)
- Network requirements: firewall rules, port requirements, connectivity between Broker VMs and Cortex Data Lake, agent-to-cloud communication paths
- Licensing and tenant configuration: understanding XSIAM editions, feature availability, and initial tenant setup procedures
- Pre-deployment assessment: evaluating existing security infrastructure, identifying integration points, and creating a deployment plan with milestones
- High availability and disaster recovery planning for Broker VM clusters and data ingestion pipelines
Common Exam Traps
Integration and Automation
The heaviest domain at 30% of the exam. Covers data source onboarding, third-party integrations, playbook creation and management, automation workflows, threat intelligence feed configuration, and scripting within playbooks. Master this domain or you will not pass.
Key Topics
Must-Know Concepts
- Data source onboarding: configuring syslog sources via Broker VM, API-based integrations, cloud connectors, and validating data ingestion with XQL queries
- Playbook creation: using the visual drag-and-drop editor, defining task types (manual, automated, conditional), setting inputs and outputs, and connecting tasks with transitions
- Playbook task types: enrichment tasks, containment actions, investigation steps, notification tasks, script execution, and integration commands
- Sub-playbooks: creating reusable playbook modules, passing inputs and outputs between parent and child playbooks, and best practices for modular design
- Conditional logic in playbooks: branching based on indicator types, severity levels, data enrichment results, and custom conditions using filters and transformers
- Content packs from Cortex Marketplace: discovering, installing, updating, and customizing pre-built integrations, playbooks, and dashboards
- Threat intelligence feed configuration: adding external threat feeds, configuring TIM scoring, automating IOC ingestion, and managing indicator expiration
- Python and PowerShell scripting: writing custom scripts within playbook tasks, handling API responses, parsing data, and error handling
- Integration instances: configuring connection parameters, authentication credentials, testing connectivity, and managing multiple instances of the same integration
- Automation debugging: testing playbooks in the playground, reviewing execution logs, identifying failed tasks, and troubleshooting automation errors
Common Exam Traps
Content Optimization
This domain covers detection engineering with IOC, BIOC, and correlation rules, XQL query writing and optimization, analytics tuning, alert management, false positive reduction, and dashboard creation. Expect scenario-based questions requiring you to choose the right detection approach and write or interpret XQL queries.
Key Topics
Must-Know Concepts
- IOC rule creation: defining indicators (hashes, IPs, domains, URLs), setting severity levels, configuring expiration, and managing rule exceptions
- BIOC rule creation: defining behavioral patterns based on process, registry, file, and network activity that map to MITRE ATT&CK techniques
- Correlation rule creation: linking events across multiple data sources and time windows, defining conditions and thresholds, and chaining rules for complex detections
- XQL query syntax: dataset selection, filter operations, field extraction, aggregation functions (comp, values_count), dedup, sort, join, union, and alter stages
- XQL performance optimization: using indexed fields in filters, limiting dataset scope, avoiding expensive operations on large datasets, and using time-range constraints
- Alert exclusion management: creating exceptions for known false positives without disabling entire rules, scoping exclusions to specific hosts or users
- Analytics module tuning: understanding pre-built analytics, adjusting thresholds, enabling or disabling specific modules, and reviewing analytics-generated alerts
- Dashboard creation: building custom dashboards with XQL-driven widgets, charts, and tables for security metrics and operational visibility
- Detection rule lifecycle: creating, testing, deploying, monitoring effectiveness, tuning thresholds, and retiring outdated rules
- Alert grouping and scoring: understanding how XSIAM groups related alerts into incidents and assigns severity scores
Common Exam Traps
Maintenance and Troubleshooting
This domain covers ongoing platform maintenance, health monitoring, troubleshooting data ingestion issues, agent management, Broker VM connectivity problems, performance optimization, audit logging, and backup and recovery. Expect questions that present a symptom and ask you to identify the root cause or corrective action.
Key Topics
Must-Know Concepts
- Health dashboard monitoring: checking data ingestion rates, identifying gaps in data collection, monitoring Broker VM connectivity status, and agent health metrics
- Data ingestion troubleshooting: diagnosing missing logs, verifying syslog source configuration, checking parser matching, and validating XDM field mapping
- Broker VM troubleshooting: connectivity issues, certificate problems, service restarts, log collection failures, and cluster node synchronization
- Agent troubleshooting: installation failures, communication issues, policy enforcement problems, and agent update mechanisms
- Performance optimization: identifying slow XQL queries, optimizing detection rule performance, managing data retention policies, and monitoring resource utilization
- Audit logging: tracking administrative actions, user activity, configuration changes, and maintaining compliance audit trails
- Backup and recovery procedures: data export, configuration backup, tenant recovery options, and disaster recovery planning
- Parser troubleshooting: identifying why ingested data is not matching expected XDM fields, testing custom parsers, and validating data normalization
- Notification and alerting: configuring health alerts for ingestion failures, Broker VM disconnections, and other platform health issues
- Platform updates and maintenance: applying patches, updating content packs, managing version compatibility, and planning maintenance windows
Common Exam Traps
XSIAM Concepts You Must Not Confuse
These pairs appear on nearly every exam. Learn the difference and you'll avoid the most common traps.
Top Mistakes to Avoid
Exam-Ready Checklist
Recommended Resources
Free & Official Resources
Paid Courses & Practice Exams
These are recommended if you prefer a structured learning path. They can save time but are not required to pass.