XSOAR-ENGINEER · Question #51
When planning a Cortex XSOAR engine deployment, which factor is most important?
The correct answer is B. Placing the engine close to integrations requiring network access. Placing the engine close to the integrations that require network access (B) is the primary deployment consideration because the XSOAR engine acts as a proxy between the XSOAR server and on-premises or network-isolated systems - high latency or unreliable connectivity between…
Question
When planning a Cortex XSOAR engine deployment, which factor is most important?
Options
- AEnsuring the engine is installed on the same host as Elasticsearch
- BPlacing the engine close to integrations requiring network access
- CUsing the largest available hardware instance
- DEnsuring the engine uses HTTPS for marketplace sync
How the community answered
(31 responses)- A6% (2)
- B74% (23)
- C3% (1)
- D16% (5)
Explanation
Placing the engine close to the integrations that require network access (B) is the primary deployment consideration because the XSOAR engine acts as a proxy between the XSOAR server and on-premises or network-isolated systems - high latency or unreliable connectivity between the engine and its target integrations directly degrades performance and reliability. Option A is wrong because the engine has no dependency on Elasticsearch; that component belongs to the XSOAR server tier. Option C is wrong because engine sizing is a secondary concern - even a modest instance placed correctly outperforms an oversized one placed far from its integrations. Option D is wrong because marketplace synchronization happens between the XSOAR server and Palo Alto's cloud, not the engine.
Memory tip: Think of the engine as a "field agent" - its value comes from being deployed on location near the systems it needs to reach, not from its hardware or where the headquarters database lives.
Topics
Community Discussion
No community discussion yet for this question.