Which two behaviors occur while an incident is closed? (Choose two.)
APlaybook is marked as complete.
BCommands cannot be executed in the War Room.
CTimers can no longer run.
DRunning timers are in a paused state.
0
Question 2
Playbook Development
0
Question 3
Incident Interactions and Reporting
0
Question 4
Use Case Planning and Development
0
Question 5
Playbook Development
0
That's the end of the Preview
This exam has 50 community-verified practice questions. Create a free account to access all questions, comments, and explanations.
Topics covered:
Planning, Installation, and MaintenanceUse Case Planning and DevelopmentPlaybook DevelopmentIncident Interactions and ReportingThreat Intelligence Management
What must happen before a pre-process rule can be applied to a potential incident?
AMapping
BPlaybook execution
CIngestion
DClassification
An engineer adds a new "Forensics" tab that includes several sections for detailed artifact analysis to the "Malware Incident" layout. However, junior analysts report they cannot see this tab, while senior analysts can.
Which configuration setting is the most likely reason for this discrepancy?
AThe underlying fields within the tab sections was incorrectly mapped.
BThe tab was not added to the junior analyst role group.
CThe tab was marked as read-only in the layout configuration for the junior analyst roles.
DA display filter was applied to the tab in the layout editor.
In a Dev/Prod deployment model, what is available only in the development tenant?
AMarketplace
BContent Repository page
CCustom integration instances
D"Export all custom content" feature
Based on the image below, how is the Domain Admin name selected when the country is "US"?
A
B
C
D
Question 6
Incident Interactions and Reporting
0
Question 7
Planning, Installation, and Maintenance
Question 8
Incident Interactions and Reporting
Question 9
Playbook Development
Question 10
Planning, Installation, and Maintenance
Question 11
Incident Interactions and Reporting
Question 12
Use Case Planning and Development
Question 13
Incident Interactions and Reporting
Question 14
Incident Interactions and Reporting
Question 15
Incident Interactions and Reporting
Question 16
Playbook Development
Question 17
Threat Intelligence Management
Question 18
Playbook Development
Question 19
Playbook Development
Question 20
Playbook Development
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ad
Want a break from the ads?
Become a Supporter and enjoy a completely ad-free experience, plus unlock Learn Mode, Exam Mode, AstroTutor AI, and more.
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Based on the image below, what will be the type of this new incident?
ACortex XDR Incident - Quasar
BCortex XDR Incident
CUnclassified
DDefault
A feed has the highest configured reliability; however, even when it sets an indicator as suspicious or benign, it has a different final verdict in Cortex XSOAR.
Based on the image below, what could be the reason for this behavior?
AIndicator Reputation from the feed is set to "Malicious."
BSource Reliability needs to be increased to "A - Completely reliable."
CThe Indicator Expiration Method needs to be set to "Never Expire."
DThe Traffic Light Protocol Color is empty.
What is an outcome of using sections within a tab when customizing an incident layout?
ATriggering specific automations or playbooks when data within that section is modified during an investigation
BEnforcing mandatory fields that must be completed before an incident can be closed
CGrouping related fields and information logically, improving readability and data entry efficiency
DRestricting access to sensitive fields based on user roles, ensuring data privacy within the specific incident type
A playbook loop that interacts with Active Directory for user details (yielding extensive data) is altered to extract newly acquired indicators of compromise (IOCs). This change results in two critical issues:
Rate limits being hit on integrated reputation services
Incidents associated with hundreds of indicators
Given the settings below, what would prevent the issues in this use case?
Incident Type: AD-Analysis -
Extract Indicators on Incident Creation: Use System Default (None)
Extract Indicators on Field Change: Inline
Mark results as note: False -
Indicator Extract Mode: Use System Default
Quiet Mode: False
ASetAD-Analysis incident creation extraction to "Extract specific indicators."
BSet ad-get-user indicator extraction mode to None.
CSet servicenow-update-ticket indicator extraction mode to Inline.
DDisable the feature that allows marking task outputs as notes.
A temporary integration issue causes a scheduled job to fail continuously.
Which action will ensure the job continues to run after future failures?
AEdit Queue Handling settings of the job.
BVerify that the "Continue on Error" box is checked in the job.
CAdjust the Role-Based Access Control (RBAC) of the incident type.
DEnsure the last playbook task runs closeInvestigation.
Which two actions will group similar incidents that share a common root cause or represent different aspects of a larger problem? (Choose two.)
ARelate Incidents
BAdd Child Incidents
CJoin Incidents
DMerge Incidents
What is needed to send a survey with multiple questions to a customer?
AData Collection
BConditional Ask
CSurvey task
DSection Header task
An incident has been created in the following state:
There is no playbook attached.
The War Room is available, but no commands have been run yet.
What is the status of the incident?
AActive
BPending
CWaiting
DIn-progress
Based on the integration and classifier configuration images below, which incident type will be created for incidents ingested using this integration when the incoming "type" field is set to "url allowed"?
AXSOAR ENGINEER- URL Alerts
BCase
CAccess
DURL Allowed
Which command adds or updates a description to an incident that can be used within widgets?
A!setIncident description="This is an updated description."
B!Set key="description" value="This is an updated description."
C!Set key-"description" value-This is an updated description.
D!setIncident description=This is an updated description.
Assuming an incident type configuration runs the associated playbook automatically, which pre-process rule action can preserve matching incidents without triggering the playbook?
AClose
BUpdate
CDrop
DLink
Two feed integrations with the same source reliability (B - Usually reliable) fetch the same indicator with the following verdicts:
Integration A - Malicious -
Integration B - Benign -
Indicator data from Integration B was fetched after Integration A.
What will be the values of the fields associated with the indicator?
AVerdict: Malicious -Other Fields: Values from Integration A
BVerdict: Malicious -Other Fields: Values from Integration B
CVerdict: Benign -Other Fields: Values from Integration A
DVerdict: Benign -Other Fields: Values from Integration B
A playbook needs to dynamically add an email sender's address to a Cortex XSOAR list named "BlockedSenders_Email."
Which built-in command should be used within the playbook to add this email address to the specified list?