XSOAR-ENGINEER Exam Questions
60 real XSOAR-ENGINEER exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1Playbook Development and Automation
A breakpoint is added to a saved playbook to ensure that it pauses before running the task "ad- delete-user." However, it is later discovered that an Active Directory account was d...
playbook breakpointsplaybook debuggingincident executionplaybook behavior - Question #2Threat Intelligence Management
What is the result of an indicator being marked as expired?
indicator lifecycleindicator expirationthreat intelligenceindicator search - Question #3User Management and Access Control
When the "Only allow these dashboards" checkbox is selected for a user role, what is the primary effect on users assigned this role?
user rolesdashboard permissionsRBACrole configuration - Question #4Incident Management and Configuration
What must happen before a pre-process rule can be applied to a potential incident?
pre-process rulesincident ingestionclassificationincident pipeline - Question #5Automation and Jobs
Which set of trigger options is available to start a job when a new instance is created?
jobsfeed triggersinstance creationautomation scheduling - Question #6Playbook Development and Automation
Based on the images below, what will be the result of the Filters and Transformers?
filterstransformersdata manipulationplaybook tasks - Question #7Integration and Data Ingestion
Which feature is used to convert event data values into incident fields when an integration fetches an event?
mappingincident fieldsevent ingestionintegration configuration - Question #8Incident Management and Configuration
A SOC team must send a notification email to specific teams based on the severity of an incident. Which feature will accomplish this task each time the severity escalates?
field-change triggerseverity escalationnotificationsincident automation - Question #9Incident Layout and Customization
What is an outcome of using sections within a tab when customizing an incident layout?
incident layouttabssectionsUI customization - Question #10Threat Intelligence Management
Which Marketplace content pack will allow sharing of threat intelligence in STIX format?
STIXTAXIIthreat intelligence sharingMarketplace content packs - Question #11Incident Layout and Customization
An engineer creates a script to display data in markdown format for a layout. When configuring the layout, the new script is not listed. Which missed configuration step will cause...
dynamic section taglayout scriptsscript configurationincident layout - Question #12Incident Layout and Customization
An engineer adds a new "Forensics" tab that includes several sections for detailed artifact analysis to the "Malware Incident" layout. However, junior analysts report they cannot s...
display filterslayout tabsrole-based visibilityincident layout - Question #13Integration and Data Ingestion
Based on the integration and classifier configuration images below, which incident type will be created for incidents ingested using this integration when the incoming "type" field...
classifierincident type mappingintegration configurationevent classification - Question #14System Administration and Deployment
What is the correct way to install different engines on the same Ubuntu machine for a Dev/Prod setup?
engine installationDev/Prod setupshell installermulti-engine deployment - Question #15Playbook Development and Automation
Which Cortex XSOAR built-in command directly updates an incident's core properties, such as severity or status?
setIncident commandincident propertiesbuilt-in commandsseverity update - Question #16Dashboards and Reporting
An organization defines Mean Time To Resolve (MTTR) as the mean time duration that an incident was open. Which widget options will generate a line graph widget showing the MTTR by...
MTTRdashboard widgetsline graphincident metrics - Question #17Playbook Development and Automation
A playbook needs to dynamically add an email sender's address to a Cortex XSOAR list named "BlockedSenders_Email." Which built-in command should be used within the playbook to add...
addToList commandXSOAR listsbuilt-in commandsplaybook automation - Question #18Threat Intelligence Management
What is the primary effect on a new file hash when it is added to the indicator exclusion list?
indicator exclusion listfile hashenrichment suppressionindicator extraction - Question #19System Administration and Deployment
In a Dev/Prod deployment model, what is available only in the development tenant?
Dev/Prod deploymentcontent repositorytenant managementdevelopment environment - Question #20Threat Intelligence Management
If a known malicious domain is no longer associated with a specific IP address, which action will make the association inactive?
indicator relationshipsrelationship revocationdomain indicatorsthreat intelligence - Question #21Incident Management and Configuration
Where is a custom layout for an incident configured?
incident layoutincident typecustom layoutXSOAR configuration - Question #22Incident Management and Configuration
When re-assigning an existing incident to a new incident type, an engineer is concerned about the preservation of critical data currently stored in fields that are only associated...
incident type reassignmentcustom fieldscontext datafield association - Question #23Automation and Playbook Development
Which two features can be used together to automatically execute a search on a remote SIEM for extracted IP Indicators? (Choose two.)
enhancement scriptintegration commandIP indicatorsSIEM search automation - Question #24Incident Management and Configuration
Based on the image below, what will be the type of this new incident?
incident classificationclassifierincident type mappingCortex XDR - Question #25Automation and Playbook Development
An engineer wants to save a command output to a custom context key using "Extend Context" in a playbook task. To do this, the engineer needs the full context path of the command's...
extend contextcontext pathraw-responseplaybook task output - Question #26Integration and Command Execution
A playbook task is set up to run an integration command that takes no input and which outputs information to the context. The integration has several instances configured. Which ac...
integration instanceusing parameterplaybook taskmulti-instance - Question #27Incident Management and Configuration
An incident has been created in the following state: - There is no playbook attached. - The War Room is available, but no commands have been run yet. What is the status of the inci...
incident statusActive statusincident lifecycleWar Room - Question #28Automation and Playbook Development
Within the playbook editor, which function allows a user to associate a task output to an incident field?
extend contextplaybook editorincident field mappingtask output - Question #29Reporting and Dashboards
What aggregates data from incidents and indicators into a Cortex XSOAR report?
widgetsreportsindicatorsincidents - Question #30Automation and Playbook Development
Based on the image below, what is the output when "Test" is clicked?
playbook task outputscript logictest modeautomation result - Question #31Threat Intelligence and Indicator Management
A feed has the highest configured reliability; however, even when it sets an indicator as suspicious or benign, it has a different final verdict in Cortex XSOAR. Based on the image...
indicator reputationfeed reliabilityindicator verdictfeed integration - Question #32Threat Intelligence and Indicator Management
Two feed integrations with the same source reliability (B - Usually reliable) fetch the same indicator with the following verdicts: - Integration A - Malicious - Integration B - Be...
feed reliabilityindicator verdictconflicting feedsbenign vs malicious - Question #33Automation and Playbook Development
Previous playbook tasks have built out the context in the image below. When specifying ${User.Name} as an input for a sub playbook task which has the default loop configuration, ho...
sub-playbook loopcontext arrayloop execution countUser.Name context - Question #34Automation and Playbook Development
Based on the image below, which key from the context points to the string GOGL?
context pathWhois outputJSON traversalcontext key - Question #35Incident Management and Configuration
What is needed to send a survey with multiple questions to a customer?
data collection tasksurveymulti-question formuser interaction - Question #36Automation and Playbook Development
A temporary integration issue causes a scheduled job to fail continuously. Which action will ensure the job continues to run after future failures?
scheduled jobcontinue on errorjob failure handlingqueue handling - Question #37Incident Management and Configuration
Which two actions will group similar incidents that share a common root cause or represent different aspects of a larger problem? (Choose two.)
relate incidentsjoin incidentsincident groupinglinked incidents - Question #38Incident Management and Configuration
Assuming an incident type configuration runs the associated playbook automatically, which pre- process rule action can preserve matching incidents without triggering the playbook?
pre-process rulesplaybook triggerupdate actionincident preservation - Question #39Automation and Playbook Development
Which command adds or updates a description to an incident that can be used within widgets?
setIncident commandincident descriptionWar Room commandwidget data - Question #40Threat Intelligence and Indicator Management
A playbook loop that interacts with Active Directory for user details (yielding extensive data) is altered to extract newly acquired indicators of compromise (IOCs). This change re...
indicator extraction moderate limitingIOC extractionad-get-user - Question #41Incident Management
Which two behaviors occur while an incident is closed? (Choose two.)
incident lifecycleWar Roomtimersincident status - Question #42Playbook Development
An engineer must create a playbook task which asks a user a single question to determine the next step in the playbook flow. Which type of task will accomplish this goal?
playbook tasksconditional taskask optionplaybook flow control - Question #43Threat Intelligence Management
What determines the current verdict for an indicator when multiple sources provide different reliability scores and verdicts?
indicator verdictsource reliabilitythreat intelligenceTIM verdict logic - Question #44Integration Development
The code snippet below is from the fetch command of an integration instance configured to run on the server. demisto.debug(f"(len(incidents)} events fetched") Where is the output f...
integration loggingdemisto.debugfetch commandintegration logs - Question #45Playbook Development
Based on the image below, how is the Domain Admin name selected when the country is "US"? A. B. C. D.
playbook conditionsinput transformerscontext dataconditional branching - Question #46Content Management
Which action will resolve the issue when an analyst upgrades a content pack from the Marketplace, and the new version has a code error?
content pack managementmarketplaceversion rollbackcontent lifecycle - Question #47Playbook Development
When using the playbook debugger, what may be the cause of a starred incident missing from the Test Data selections?
playbook debuggertest dataincident restrictionsdebugging troubleshooting - Question #48Incident Management
What is the unique identifier for a note in the incident War Room?
War Roomentry IDincident notesidentifiers - Question #49System Administration and Configuration
Where does the mapping of user groups to SAML groups take place?
SAMLuser group mappingauthenticationtenant configuration - Question #50Threat Intelligence Management
When the verdict of an indicator is set manually, which source reliability does it receive?
indicator verdictsource reliabilitymanual verdict overrideTIM