Palo Alto Networks XSOAR Engineer - XSOAR-Engineer Exam Practice Test
If a known malicious domain is no longer associated with a specific IP address, which action will make the association inactive?.
Correct Answer: D
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
In which two options can an automation script be executed? (Choose two.)
Correct Answer: A,B
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
An incident field is created having the display name as Source_IP. How can the field be accessed?
Correct Answer: B
Vote an answer
Where would you look to find a personalized view of your own incidents and tasks?
Correct Answer: C
Vote an answer
Where are incident layouts customized?
Correct Answer: C
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
The XSOAR administrator is writing an automation and would like to return an error entry back into XSOAR if a particular command errors out. How can this be achieved?
Correct Answer: B
Vote an answer
What is the correct expression to use when filtering only PDF files?
Correct Answer: B
Vote an answer
Which two statements describe how timers are configured to start and stop automatically in a playbook?
(Choose two.)
(Choose two.)
Correct Answer: B,D
Vote an answer
What are two primary uses of standard tasks? (Choose two.)
Correct Answer: A,C
Vote an answer
An administrator has noticed that an integration has failed to fetch incidents. Where would they go to download logs to troubleshoot the error?
Correct Answer: A
Vote an answer
What is the most effective way to correlate multiple raw events coming from a SIEM and link them together?
Correct Answer: A
Vote an answer
Which three options can be defined in the layout settings? (Choose three.)
Correct Answer: A,B,E
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
What is the unique identifier for a note in the incident War Room?.
Correct Answer: C
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
What must happen before a pre-process rule can be applied to a potential incident?.
Correct Answer: C
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
In Cortex XSOAR multi tenant setup, when content from a development server is pushed to the remote repository, where in the production server can the updates be found?
Correct Answer: D
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).