An administrator has noticed that an integration has failed to fetch incidents. Where would they go to download logs to troubleshoot the error?
An incident has been created in the following state:
There is no playbook attached.
The War Room is available, but no commands have been run yet.
What is the status of the incident?.
In Cortex XSOAR multi tenant setup, when content from a development server is pushed to the remote repository, where in the production server can the updates be found?
You can customize most aspects of the incident layout, including which three of the following? (Choose three.)
Two feed integrations with the same source reliability (B - Usually reliable) fetch the same indicator with the following verdicts:
Integration A - Malicious
Integration B - Benign
Indicator data from Integration B was fetched after Integration A.
What will be the values of the fields associated with the indicator?.
On the System Diagnostics page, what is the default minimum size for a Work Plan to be considered big?
An XSOAR engineer has been tasked with exporting all indicators from the production environment in the last 90 days. The final report needs to be in CSV format containing all indicator fields. How can this task be achieved?
When developing the playbook, which of the following can be used by a XSOAR Administrator?
An automation returned an output called: csvReport.
What filter would be used to check if the automation returned results?
Which field type provides an interactive and editable display of table-based data?
Which two input requirements are needed to train a machine learning model? (Choose two.)
Which tag must be applied to an Automation Script in order for it to be available when configuring an Indicator Type?
A breakpoint is added to a saved playbook to ensure that it pauses before running the task "ad-delete-user." However, it is later discovered that an Active Directory account was deleted by this playbook, and the playbook did not pause at the breakpoint.
What is the cause of this issue?.
What is the most effective way to correlate multiple raw events coming from a SIEM and link them together?
When creating an incident layout section, it is best to place long field values within which of the following?
What determines the current verdict for an indicator when multiple sources provide different reliability scores and verdicts?.
A large number of incidents were deleted by mistake.
Which two architecture components can be used to recover the lost data? (Choose two.)
Management would like to get an incident report automatically following an incident’s closure. How would this be accomplished?
Which Marketplace content pack will allow sharing of threat intelligence in STIX format?.
What are the out-of-the-box aggregate values that can be applied on widgets data?
An engineer deployed two different instances of Active Directory for each organization site. As part of account enrichment use case, the engineer would like to delete a user from one specific site.
Which command will accomplish this?
After executing the DeleteContext automation with all=yes argument, how would the context data of an incident present?
An organization has recently acquired another company as its subsidiary. The subsidiary has its infrastructure on AWS cloud as illustrated in the image below:

The organization wants to use the mail server location on the subsidiary's cloud to send emails. Without acquiring additional licenses, which XSOAR component can fulfill the requirement?
Which XSOAR architecture would be recommended for Managed Security Service Providers (MSSP)?
Within the playbook editor, which function allows a user to associate a task output to an incident field?.
Which of these would be the most operationally efficient repository for moving XSOAR custom content from a development server to a production environment?
Incidents need to be filtered by all of the following criteria:
1.Status – Pending
2.Exclude Category – Job
3.Severity – High
4.Owner – None (No owner assigned)
5.Type – Phishing
6.Email Subject – “You have won a million dollars”
What is the correct query syntax for the above incident search filter?
Which two solutions are available to scale an overloaded XSOAR environment? (Choose two.)
An incident field is created having the display name as Source_IP. How can the field be accessed?
When the "Only allow these dashboards" checkbox is selected for a user role, what is the primary effect on users assigned this role?.
An engineer creates a script to display data in markdown format for a layout. When configuring the layout, the new script is not listed.
Which missed configuration step will cause this behavior?.
An Engineer wants to filter a csvList value according to a dynamic value saved under the test context key.
Which three values would save the test context key? (Choose three.)
A SOC analyst needs to retrieve the list of all open phishing incidents in the last 30 days. What is the correct query to use?
A playbook needs to dynamically add an email sender's address to a Cortex XSOAR list named "BlockedSenders_Email."
Which built-in command should be used within the playbook to add this email address to the specified list?.
Based on the image below, which key from the context points to the string GOGL?.

What happens if both a Classifier and Incident Type are configured in an integration instance's settings?
How would context data be filtered to receive only malicious indicator values with DBotScore?
An engineer would like to add a custom field to the New Job form for a job triggered from a threat intel feed. How would the engineer implement this?
What is an outcome of using sections within a tab when customizing an incident layout?.
Which of the following is a basic setting that can be configured in an automation?
Which two causes may be occurring if an integration test is working, but the integration is not fetching incidents? (Choose two.)