XSOAR-ENGINEER Exam Questions
58 real XSOAR-ENGINEER exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1
A breakpoint is added to a saved playbook to ensure that it pauses before running the task "ad- delete-user." However, it is later discovered that an Active Directory account was d...
- Question #2
What is the result of an indicator being marked as expired?
- Question #3
When the "Only allow these dashboards" checkbox is selected for a user role, what is the primary effect on users assigned this role?
- Question #4
What must happen before a pre-process rule can be applied to a potential incident?
- Question #5
Which set of trigger options is available to start a job when a new instance is created?
- Question #6
Based on the images below, what will be the result of the Filters and Transformers?
- Question #7
Which feature is used to convert event data values into incident fields when an integration fetches an event?
- Question #8
A SOC team must send a notification email to specific teams based on the severity of an incident. Which feature will accomplish this task each time the severity escalates?
- Question #9
What is an outcome of using sections within a tab when customizing an incident layout?
- Question #10
Which Marketplace content pack will allow sharing of threat intelligence in STIX format?
- Question #11
An engineer creates a script to display data in markdown format for a layout. When configuring the layout, the new script is not listed. Which missed configuration step will cause...
- Question #12
An engineer adds a new "Forensics" tab that includes several sections for detailed artifact analysis to the "Malware Incident" layout. However, junior analysts report they cannot s...
- Question #13
Based on the integration and classifier configuration images below, which incident type will be created for incidents ingested using this integration when the incoming "type" field...
- Question #14
What is the correct way to install different engines on the same Ubuntu machine for a Dev/Prod setup?
- Question #15
Which Cortex XSOAR built-in command directly updates an incident's core properties, such as severity or status?
- Question #17
A playbook needs to dynamically add an email sender's address to a Cortex XSOAR list named "BlockedSenders_Email." Which built-in command should be used within the playbook to add...
- Question #18
What is the primary effect on a new file hash when it is added to the indicator exclusion list?
- Question #19
In a Dev/Prod deployment model, what is available only in the development tenant?
- Question #20
If a known malicious domain is no longer associated with a specific IP address, which action will make the association inactive?
- Question #21
Where is a custom layout for an incident configured?
- Question #22
When re-assigning an existing incident to a new incident type, an engineer is concerned about the preservation of critical data currently stored in fields that are only associated...
- Question #23
Which two features can be used together to automatically execute a search on a remote SIEM for extracted IP Indicators? (Choose two.)
- Question #24
Based on the image below, what will be the type of this new incident?
- Question #25
An engineer wants to save a command output to a custom context key using "Extend Context" in a playbook task. To do this, the engineer needs the full context path of the command's...
- Question #26
A playbook task is set up to run an integration command that takes no input and which outputs information to the context. The integration has several instances configured. Which ac...
- Question #27
An incident has been created in the following state: - There is no playbook attached. - The War Room is available, but no commands have been run yet. What is the status of the inci...
- Question #28
Within the playbook editor, which function allows a user to associate a task output to an incident field?
- Question #29
What aggregates data from incidents and indicators into a Cortex XSOAR report?
- Question #30
Based on the image below, what is the output when "Test" is clicked?
- Question #31
A feed has the highest configured reliability; however, even when it sets an indicator as suspicious or benign, it has a different final verdict in Cortex XSOAR. Based on the image...
- Question #32
Two feed integrations with the same source reliability (B - Usually reliable) fetch the same indicator with the following verdicts: - Integration A - Malicious - Integration B - Be...
- Question #33
Previous playbook tasks have built out the context in the image below. When specifying ${User.Name} as an input for a sub playbook task which has the default loop configuration, ho...
- Question #34
Based on the image below, which key from the context points to the string GOGL?
- Question #35
What is needed to send a survey with multiple questions to a customer?
- Question #36
A temporary integration issue causes a scheduled job to fail continuously. Which action will ensure the job continues to run after future failures?
- Question #37
Which two actions will group similar incidents that share a common root cause or represent different aspects of a larger problem? (Choose two.)
- Question #38
Assuming an incident type configuration runs the associated playbook automatically, which pre- process rule action can preserve matching incidents without triggering the playbook?
- Question #39
Which command adds or updates a description to an incident that can be used within widgets?
- Question #40
A playbook loop that interacts with Active Directory for user details (yielding extensive data) is altered to extract newly acquired indicators of compromise (IOCs). This change re...
- Question #41
Which two behaviors occur while an incident is closed? (Choose two.)
- Question #42
An engineer must create a playbook task which asks a user a single question to determine the next step in the playbook flow. Which type of task will accomplish this goal?
- Question #43
What determines the current verdict for an indicator when multiple sources provide different reliability scores and verdicts?
- Question #44
The code snippet below is from the fetch command of an integration instance configured to run on the server. demisto.debug(f"(len(incidents)} events fetched") Where is the output f...
- Question #46
Which action will resolve the issue when an analyst upgrades a content pack from the Marketplace, and the new version has a code error?
- Question #47
When using the playbook debugger, what may be the cause of a starred incident missing from the Test Data selections?
- Question #48
What is the unique identifier for a note in the incident War Room?
- Question #49
Where does the mapping of user groups to SAML groups take place?
- Question #50
When the verdict of an indicator is set manually, which source reliability does it receive?
- Question #51
When planning a Cortex XSOAR engine deployment, which factor is most important?
- Question #52
Which two tasks are essential when planning a dev/prod XSOAR deployment? (Choose two)