XSIAM-ENGINEER Exam Questions
67 real XSIAM-ENGINEER exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1
Which two requirements must be met for a Cortex XDR agent to successfully use the Broker VM as a download source for content updates? (Choose two.)
- Question #2
During a new Cortex XSIAM deployment, a user consistently experiences timeout sessions while trying to connect to the agent through Live Terminal, even though the firewall engineer...
- Question #3
Which step must be taken to enable Cloud Identity Engine on Cortex XSIAM?
- Question #5
When Cortex XDR agents are on servers in a zone with no internet access, which configuration will keep them communicating with the platform?
- Question #6
Which installer type should be used when upgrading a non-Linux Kubernetes cluster?
- Question #7
A systems engineer overseeing the integration of data from various sources through data pipelines into Cortex XSIAM notices modifications occurring during the ingestion process, an...
- Question #8
A security engineer notices that in the past week ingestion has spiked significantly. Upon investigating the anomaly, it is determined that a custom application developed in-house...
- Question #9
An engineer is conducting a threat actor emulated test to determine which Cortex XDR module would provide protection or alert on a real-world attack. The first test was prevented....
- Question #10
A Cortex XSIAM engineer adds a disable injection and prevention rule for a specific running process. After an hour, the engineer disables the rule to reinstate the security capabil...
- Question #11
What is the function of the "MODEL" section when creating a data model rule?
- Question #12
What is the primary benefit of setting the "--memory-swap" option to "-1" during Cortex XSIAM engine deployment?
- Question #13
A CISO has asked an engineer to create a custom dashboard in Cortex XSIAM that can be filtered to show incidents assigned to a specific user. Which feature should be used to filter...
- Question #14
How can a Cortex XSIAM engineer resolve the issue when a SOC analyst escalates missing details after merging two similar incidents?
- Question #15
Which cytool command will look up the policy being applied to a Cortex XDR agent?
- Question #16
A file for a support exception that needs to be updated locally on a Linux endpoint has been supplied. Which cytool command will upload this support exception file to the endpoint?
- Question #17
A Cortex XSIAM engineer plans to add Kafka and Syslog Collectors to a Broker VM cluster. What are two expected behaviors of the applets when they are added to the cluster? (Choose...
- Question #18
Based on the _raw_log and XQL query information below, what will be the result(s) of the temp_value?
- Question #19
When activating the Cortex XSIAM tenant, how is the data at rest configured with AES 128 encryption?
- Question #20
A sub-playbook is configured to loop with a For Each Input. The following inputs are given to the sub-playbook: Input x: W,X,Y,Z Input y: a,b,c,d Input z: 9 Which inputs will be us...
- Question #21
The following string is a value of a key named "Data2" in the context: {"@admin":"admin","@dirtyld":"1","@loc":"Lab","@name":"default‐1","@oldname":"Test","@time": "2024/08/28 07:4...
- Question #22
A Cortex XDR agent is installed on an endpoint, but the agent is unable to download content updates and has not registered with the Cortex XSIAM server. An engineer troubleshoots t...
- Question #23
A Behavioral Threat Protection (BTP) alert is triggered with an action of "Prevented (Blocked)" on one of several application servers running Windows Server 2022. The investigation...
- Question #24
Which action will prevent the automatic extraction of indicators such as IP addresses and URLs from a script's output?
- Question #25
An application which ingests custom application logs is hosted in an on-premises virtual environment on an Ubuntu server, and it logs locally to a .csv file. Which set of actions w...
- Question #26
Which action is required to enable use of a custom script in an alert layout?
- Question #27
What is the reason all Broker VM options are greyed out when a user attempts to select a Broker VM as a download source in the Agent Settings profile?
- Question #28
What is a key characteristic of a parsing rule in Cortex XSIAM?
- Question #29
Which type of parsing error is categorized in the dataset "parsing_rules_errors"?
- Question #30
Before initiating a malware scan action on a Linux workstation, an engineer notices that the Cortex XDR agent's operational status on the workstation is reporting as "partially pro...
- Question #31
A Cortex XSIAM engineer is implementing role-based access control (RBAC) and scope-based access control (SBAC) for users accessing the Cortex XSIAM tenant with the following requir...
- Question #32
Administrators from Building 3 have been added to Cortex XSIAM to perform limited functions on a subset of endpoints. Custom roles have been created and applied to the administrato...
- Question #33
While using the playbook debugger, an engineer attaches the context of an alert as test data. What happens with respect to the interactions with the list objects via tasks in this...
- Question #34
What is the primary function of the URL "https://<region>-docker.pkg.dev" in the context of a Palo Alto Networks infrastructure?
- Question #35
Which component is responsible for identifying the correct parsing rule to apply for a unique data source in Cortex XSIAM?
- Question #36
When a newly installed agent is not reporting telemetry to Cortex XSIAM, which two steps should you check first? (Choose two)
- Question #37
Before updating the XDR Collector, what should an administrator verify to avoid disruption?
- Question #38
How will Cortex XSIAM help with raw log ingestion from third-party sources in an existing infrastructure?
- Question #39
In which two locations can correlation rules be monitored for errors? (Choose two.)
- Question #40
Which option should be used when customizing a dashboard in Cortex XSIAM to include a widget that will display data filtered by more than one dynamic value?
- Question #41
How must Cloud Identity Engine be deployed and activated on Cortex XSIAM?
- Question #42
Which common issue can result in sudden data ingestion loss for a data source that was previously successful?
- Question #43
While using the remote repository on a Development XSIAM tenant, which two objects can be pushed or pulled to the remote repository? (Choose two.)
- Question #44
When a Cortex XSIAM playbook execution reaches a breakpoint on a non-manual task, which two actions will allow the playbook to continue? (Choose two.)
- Question #45
What is the purpose of using rolling tokens to manage Cortex XDR agents?
- Question #46
Based on the image below, which statement applies to the ability to remove tabs when creating a new alert layout?
- Question #47
A Cortex XSIAM engineer is developing a playbook that uses reputation commands such as '!ip' to enrich and analyze indicators. Which statement applies to the use of reputation comm...
- Question #48
An engineer wants to onboard data from a third-party vendor's firewall. There is no content pack available for it, so the engineer creates custom data source integration and parsin...
- Question #49
Why is it important to understand the organization's current threat detection capabilities before deploying XSIAM?
- Question #50
How can administrators validate the effectiveness of exclusion rules in Cortex XSIAM? (Choose two)
- Question #51
To enable authentication integration for automated user provisioning in Cortex XSIAM, what steps are essential?