XSOAR-Engineer Palo Alto Networks XSOAR Engineer Questions and Answers
When the verdict of an indicator is set manually, which source reliability does it receive?.
Which command adds or updates a description to an incident that can be used within widgets?
Which command adds or updates a description to an incident that can be used within widgets?.
Two feed integrations with the same source reliability (B - Usually reliable) fetch the same indicator with the following verdicts:
Integration A - Malicious
Integration B - Benign
Indicator data from Integration B was fetched after Integration A.
What will be the values of the fields associated with the indicator?.
Based on the image below, which key from the context points to the string GOGL?.

What determines the current verdict for an indicator when multiple sources provide different reliability scores and verdicts?.
A playbook needs to dynamically add an email sender's address to a Cortex XSOAR list named "BlockedSenders_Email."
Which built-in command should be used within the playbook to add this email address to the specified list?.
An analyst runs the following command in a playbook task:
!ip ip=1.1.1.1
Which extraction mode needs to be enabled on the Advanced tab of the playbook task to synchronously extract indicators from the results of this command?
On the System Diagnostics page, what is the default minimum size for a Work Plan to be considered big?
An engineer would like to change an incident’s SLA according to the severity field changes. How can the engineer achieve this task?
What are the three ways to add/mark entries as evidence inside the Evidence Board? (Choose three.)
When developing the playbook, which of the following can be used by a XSOAR Administrator?
Inside the Incidents table view, which actions can be performed on the selected incidents? (Choose two.)
Based on the integration and classifier configuration images below,

which incident type will be created for incidents ingested using this integration when the incoming "type" field is set to "url allowed"?.
Which two options will troubleshoot an integration’s fetch incidents command? (Choose two.)
An XSOAR engineer has been tasked with exporting all indicators from the production environment in the last 90 days. The final report needs to be in CSV format containing all indicator fields. How can this task be achieved?
When using the playbook debugger, what may be the cause of a starred incident missing from the Test Data selections?.
After executing the DeleteContext automation with all=yes argument, how would the context data of an incident present?
Which three types of information are displayed on the incident Quick View? (Choose three.)
If a known malicious domain is no longer associated with a specific IP address, which action will make the association inactive?.
Which three authentication methods are supported when logging into XSOAR? (Choose three.)
What happens if both a Classifier and Incident Type are configured in an integration instance's settings?
An administrator wants to run an automation in the War Room to set the incident field "Description" to "Confirmed Phishing". Which command should they enter in the War Room CLI?
A large number of incidents were deleted by mistake.
Which two architecture components can be used to recover the lost data? (Choose two.)
Assuming an incident type configuration runs the associated playbook automatically, which pre-process rule action can preserve matching incidents without triggering the playbook?.
Within the playbook editor, which function allows a user to associate a task output to an incident field?.
Which option is available in XSOAR to create the body of a Threat Intel Report?
Which two features does XSOAR offer to help recover from a server failure? (Choose two.)
For troubleshooting, after a log bundle is created, where do the logs appear on the XCSOAR server?
An incident field is created having the display name as Source_IP. How can the field be accessed?
Management would like to get an incident report automatically following an incident’s closure. How would this be accomplished?
An XSOAR Engineer has developed a playbook and would like to contribute it to the XSOAR Marketplace to share with other users.
Which two options are available to the Engineer for contributing to the Marketplace? (Choose two.)
The XSOAR administrator is writing an automation and would like to return an error entry back into XSOAR if a particular command errors out. How can this be achieved?
Based on the images below,

what will be the result of the Filters and Transformers?.
An administrator has noticed that an incident fetch has failed, causing several internal workflows to be backed up. The administrator would like to receive notifications the next time the incident fetch fails.
How can they achieve this?
Incidents need to be filtered by all of the following criteria:
1.Status – Pending
2.Exclude Category – Job
3.Severity – High
4.Owner – None (No owner assigned)
5.Type – Phishing
6.Email Subject – “You have won a million dollars”
What is the correct query syntax for the above incident search filter?
During configuration of the inputs of a sub-playbook in the main playbook, there is an option under the Loop tab called "For Each Input". What is this option used to?
Which of the following does a XSOAR Admin need to create an integration with a third party cloud application?
Which two actions will group similar incidents that share a common root cause or represent different aspects of a larger problem? (Choose two.).
A SOC team must send a notification email to specific teams based on the severity of an incident.
Which feature will accomplish this task each time the severity escalates?.
Which of the following is a prerequisite to editing out-of-the-box (OOTB) content?
Which three scripting languages can an engineer use to write XSOAR automations? (Choose three.)
A SOC analyst needs to retrieve the list of all open phishing incidents in the last 30 days. What is the correct query to use?
Which two methods will allow data to be saved in incident fields within a playbook? (Choose two.)
What is used to trigger playbooks automatically based on the classification of an incident?
Which two options may be added when a content pack is being installed? (Choose two.)

