XSOAR Engineer Practice Test — 47 Free Questions Online
QuestionQ1
Playbook Development
Save question
A playbook task is configured to run an integration command that accepts no input and outputs information to the context. The integration has multiple instances configured.
Which action ensures that the integration command runs only once?
ASpecify the using- parameter to target a specific integration instance to run.
BClick on Advanced Options Limits to specify the minimum / maximum run limits for a command.
CClick on Performance Run Limits to specify the maximum run count before the task exits.
DSpecify the runlimit= parameter to limit the number of times a specific command will run.
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ2
Planning, Installation, and Maintenance
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ3
Playbook Development
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ4
Incident Interactions and Reporting
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ5
Playbook Development
0
Community Discussion
No comments yet. Be the first to start the discussion!
That's the end of the preview
It's free
100% of the questions are free for all users. No strings attached.
Planning, Installation, and MaintenanceUse Case Planning and DevelopmentPlaybook DevelopmentIncident Interactions and ReportingThreat Intelligence Management
When the Only allow these dashboards checkbox is selected for a user role, what is the primary impact on users assigned to that role?
AThey are prompted to select their preferred dashboards upon login and can only modify these chosen dashboards.
BThey can only view specified dashboards and make minor modifications.
CThey will automatically have all dashboards that are shared with them added to their view.
DThey will be restricted to viewing only the specified default dashboards and cannot make any modifications.
Based on the image shown, what is the output after Test is clicked?
AOrange
BBlue
CYellow
DRed
Which command can add or update an incident description that may be used in widgets?
A!setIncident description="This is an updated description."
B!Set key="description" value="This is an updated description."
C!Set key-"description" value-This is an updated description.
D!setIncident description=This is an updated description.
A playbook loop that queries Active Directory for user details, producing extensive data, is changed to extract newly acquired indicators of compromise (IOCs). This modification creates two critical issues:
Rate limits are reached on integrated reputation services.
Incidents are associated with hundreds of indicators.
Given the following settings, what would prevent these issues in this use case?
Incident Type: AD-Analysis -
Extract Indicators on Incident Creation: Use System Default (None)
Extract Indicators on Field Change: Inline
Task 1: ad-get-user -
Mark results as note: False -
Indicator Extract Mode: Inline -
Quiet Mode: False -
Task 2: ad-disable-account -
Mark results as note: True -
Indicator Extract Mode: None -
Quiet Mode: True -
Task 3: servicenow-update-Lickel.
Mark results as note: False -
Indicator Extract Mode: Use System Default
Quiet Mode: False
ASetAD-Analysis incident creation extraction to "Extract specific indicators."
BSet ad-get-user indicator extraction mode to None.
CSet servicenow-update-ticket indicator extraction mode to Inline.
DDisable the feature that allows marking task outputs as notes.
QuestionQ6
Playbook Development
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Threat Intelligence Management
QuestionQ8
Incident Interactions and Reporting
QuestionQ9
Incident Interactions and Reporting
QuestionQ10
Threat Intelligence Management
QuestionQ11
Planning, Installation, and Maintenance
QuestionQ12
Threat Intelligence Management
QuestionQ13
Threat Intelligence Management
QuestionQ14
Use Case Planning and Development
QuestionQ15
Planning, Installation, and Maintenance
QuestionQ16
Incident Interactions and Reporting
QuestionQ18
Planning, Installation, and Maintenance
QuestionQ20
Incident Interactions and Reporting
QuestionQ22
Playbook Development
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
An engineer needs to create a playbook task that asks a user one question to decide the next step in the playbook flow.
Which task type achieves this objective?
AStandard task using manual task settings
BData collection task using the task option
CConditional task using the ask option
DData collection task using the generated link option
When an indicator’s verdict is manually set, which source reliability is assigned to it?
AF - reliability cannot be found
BA
CUndefined
DA+++
An engineer adds a new "Forensics" tab, containing several sections for detailed artifact analysis, to the "Malware Incident" layout. However, junior analysts say they cannot see the tab, whereas senior analysts can.
Which configuration setting most likely causes this discrepancy?
AThe underlying fields within the tab sections was incorrectly mapped.
BThe tab was not added to the junior analyst role group.
CThe tab was marked as read-only in the layout configuration for the junior analyst roles.
DA display filter was applied to the tab in the layout editor.
Which built-in Cortex XSOAR command directly updates an incident’s core properties, such as severity or status?
AaddEntry
BupdateContext
CsetIncident
Dset
Which Marketplace content pack enables the sharing of threat intelligence in STIX format?
AExternal dynamic list
BMISP Server
CGeneric Export Indicators Service
DTAXII Server
Which action resolves the problem when an analyst upgrades a content pack from the Marketplace and the new version contains a code error?
ARevert the content pack to a previous version.
BUninstall and reinstall the content pack.
CUpgrade the dependencies of the content pack.
DExport and manually upload the content pack.
What is the primary effect on a new file hash when it is added to the indicator exclusion list?
AIt is not extracted, enriched, or given a new verdict.
BIt is extracted and stored, but an "exclusion" tag is added, requiring manual review before it can affect any incidents.
CIt is processed normally by enrichment automations, but the verdict is set to "benign."
DIt is excluded from intelligence feeds that have a reliability score lower than "B - Usually reliable."
What determines an indicator’s current verdict when multiple sources supply different reliability scores and verdicts?
AVerdict provided by the most recently updated source
BAverage verdict score from all sources
CVerdict provided by the source with the highest reliability score
DHighest severity verdict from all sources
Based on the images below, what is the outcome of the Filters and Transformers?
ASelma Moon
BRichardson Morales
CHubbard Wilcox
DMichael Henderson
The code snippet below appears in the fetch command of an integration instance configured to run on the server.
Where is the output from this snippet located when the instance performs an automatic fetch?
AIncident labels
BPlatform Log bundle
CIntegration Logs table
DWar Room entry
An incident has been created with the following state:
No playbook is attached.
The War Room is available, but no commands have yet run.
What is the incident’s status?
AActive
BPending
CWaiting
DIn-progress
An engineer develops a script that displays data in Markdown format for a layout. While configuring the layout, the new script does not appear.
Which omitted configuration step causes this behavior?
ATagging the script with Dynamic Section
BEnsuring the script has the necessary permissions
CAdding the snippet as an integration command
DUsing a markdown output type
Based on the integration and classifier configuration below, which incident type will be created for incidents ingested through this integration when the incoming type field is set to url allowed?
AXSOAR ENGINEER- URL Alerts
BCase
CAccess
DURL Allowed
A playbook must dynamically add an email sender's address to a Cortex XSOAR list called BlockedSenders_Email.
Which built-in command should the playbook use to add this email address to the specified list?
Community Discussion