PCSAE Palo Alto Networks Certified Security Automation Engineer Questions and Answers
Which two reasons would lead an engineer to create a custom widget? (Choose two.)
An engineer notices that playbooks only start once the user clicks the ‘investigate’ button and he/she would like the playbook to start automatically.
How can this be implemented?
Inside the Incidents table view, which actions can be performed on the selected incidents? (Choose two.)
An administrator has noticed that an incident fetch has failed, causing several internal workflows to be backed up. The administrator would like to receive notifications the next time the incident fetch fails.
How can they achieve this?
When uploading content, which two options could the upload include? (Choose two.)
In order to automatically run a playbook on the indicators fetched by an integration, what would an XSOAR Administrator setup?

Given the following context data, what would be the expected output of the expression?
A large number of incidents were deleted by mistake.
Which two architecture components can be used to recover the lost data? (Choose two.)
Which field type should be used to hold more than 60,000 characters of unformatted text?
Which of these would be the most operationally efficient repository for moving XSOAR custom content from a development server to a production environment?
Which two advanced attributes can be applied to incident fields when editing? (Choose two.)
Newly created subplaybooks do not have any inputs, or outputs. What is necessary to make them functional? (Choose two.)
Which two statements describe how timers are configured to start and stop automatically in a playbook? (Choose two.)
A SOC analyst needs to retrieve the list of all open phishing incidents in the last 30 days. What is the correct query to use?
Which two options are the most effective for moving content between two environments? (Choose two.)
An engineer asked for a specific command in an integration but the capability does not exist. The engineer decided to edit the existing integration by copying the integration and adding the needed commands.
What is the main concern when adding these commands?
An analyst wants to run a script to remove usernames from an incident before the incident becomes active in XSOAR. How can this be achieved?
Which two solutions are available to scale an overloaded XSOAR environment? (Choose two.)
What are the out-of-the-box aggregate values that can be applied on widgets data?
While testing a custom integration, an XSOAR engineer noticed that the incident fetch interval is missing. How can this be fixed?
You need to retrieve a list of all malicious hashes over the last 30 days. What is the correct query to use?
Which of the following is a prerequisite to editing out-of-the-box (OOTB) content?
Which XSOAR architecture would be recommended for Managed Security Service Providers (MSSP)?
A Cortex XSOAR Administrator is tasked with building a button for an analyst in order for the analyst to be assigned to the incident as an owner. What is the process?
Which three types of information are displayed on the incident Quick View? (Choose three.)
In which two scenarios would it be appropriate to implement a loop for a sub-playbook? (Choose two.)
Which field type provides an interactive and editable display of table-based data?
Which two situations would an engineer consider when configuring classification and mapping for an incident type? (Choose two.)


