New Year Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

XSOAR-Engineer Palo Alto Networks XSOAR Engineer Questions and Answers

Questions 4

An administrator has noticed that an integration has failed to fetch incidents. Where would they go to download logs to troubleshoot the error?

Options:

A.

Go to the Marketplace > Download the Fix my XSOAR playbook pack > Run the playbook > Download logs from War Room

B.

Settings > About > Troubleshooting > Set Log Level to Debug > Download Logs

C.

DashboardsandReports > System Health

D.

Settings > About > System Diagnostics

Buy Now
Questions 5

An incident has been created in the following state:

There is no playbook attached.

The War Room is available, but no commands have been run yet.

What is the status of the incident?.

Options:

A.

Active.

B.

Pending.

C.

Waiting.

D.

In-progress.

Buy Now
Questions 6

In Cortex XSOAR multi tenant setup, when content from a development server is pushed to the remote repository, where in the production server can the updates be found?

Options:

A.

Main Account

B.

Tenants

C.

Agent tools

D.

Marketplace

Buy Now
Questions 7

You can customize most aspects of the incident layout, including which three of the following? (Choose three.)

Options:

A.

Which users have permissions to view the tabs

B.

Which roles have permissions to view the tabs

C.

Which dashboard settings are applied

D.

The information and how is it displayed

E.

Which tabs appear and in which order

Buy Now
Questions 8

Two feed integrations with the same source reliability (B - Usually reliable) fetch the same indicator with the following verdicts:

Integration A - Malicious

Integration B - Benign

Indicator data from Integration B was fetched after Integration A.

What will be the values of the fields associated with the indicator?.

Options:

A.

Verdict: Malicious

Other Fields: Values from Integration A.

B.

Verdict: Malicious

Other Fields: Values from Integration B.

C.

Verdict: Benign

Other Fields: Values from Integration A.

D.

Verdict: Benign

Other Fields: Values from Integration B.

Buy Now
Questions 9

Which playbook will a job run by default?

Options:

A.

The playbook assigned to the incident type

B.

The playbook assigned to the indicator type

C.

The playbook assigned during pre-processing

D.

The playbook assigned by the integration

Buy Now
Questions 10

Which method accesses a field called ‘User Mail’ in a playbook?

Options:

A.

${incident.usermail}

B.

${incident.User Mail}

C.

${incident.UserMail}

D.

${usermail}

Buy Now
Questions 11

On the System Diagnostics page, what is the default minimum size for a Work Plan to be considered big?

Options:

A.

2MB

B.

3MB

C.

1MB

D.

5MB

Buy Now
Questions 12

An XSOAR engineer has been tasked with exporting all indicators from the production environment in the last 90 days. The final report needs to be in CSV format containing all indicator fields. How can this task be achieved?

Options:

A.

Run the command !GetIndicatorsByQuery in CLI with its default arguments and export all indicators in the last 90 days.

B.

SSH into the server and copy the indicator's database.

C.

In the Threat Intel page, add query firstSeen:>="90 days ago", select All columns in Table View, and click Export to export as a CSV.

D.

Run the command !findIndicators in CLI with the query firstSeen:>="90 days ago" and export to CSV.

Buy Now
Questions 13

When developing the playbook, which of the following can be used by a XSOAR Administrator?

Options:

A.

The Debugger panel to test data with one of last five incidents. This will affect the incident’s original incident data.

B.

Context data from existing incidents by exporting the YAML data from incidents and importing it to playbook editor.

C.

Debugger panel and XML data from a similar incident with New Mock Incident. This will not affect the incidents original incident data.

D.

The Debugger panel to test data with one of last fifty incidents. This will not affect the incident’s original incident data.

Buy Now
Questions 14

An automation returned an output called: csvReport.

What filter would be used to check if the automation returned results?

Options:

A.

Contains/Includes

B.

Equals/Matches

C.

In/In list

D.

Is defined/Exist

Buy Now
Questions 15

Which field type provides an interactive and editable display of table-based data?

Options:

A.

HTML

B.

Grid (table)

C.

Markdown

D.

Multi Select

Buy Now
Questions 16

Which two input requirements are needed to train a machine learning model? (Choose two.)

Options:

A.

3000 Incidents

B.

Incident Field

C.

Verdict Label

D.

Incident Type

Buy Now
Questions 17

Which tag must be applied to an Automation Script in order for it to be available when configuring an Indicator Type?

Options:

A.

reputation-script

B.

enrich

C.

reputationScript

D.

reputation

Buy Now
Questions 18

Whar are possible war room result (entry) types?

Options:

A.

Context, file, error, image

B.

Note, indicator, error, image

C.

Video, file, error, image

D.

Note, file, error, image

Buy Now
Questions 19

What is the function of timer SLA fields in Cortex XSOAR?

Options:

A.

To track SLA breaches per playbook

B.

To run a script that executes on SLA assignment

C.

To automatically alert the analyst on SLA breach

D.

To count the time between one or more tasks

Buy Now
Questions 20

What is the correct expression to use when filtering only PDF files?

Options:

A.

Use File.Extension that does not equal (string comparison) PDF

B.

Use File.Name contains PDF

C.

Use File.Extension contains (general) PDF

D.

Use File.Extension equals (string comparison) PDF

Buy Now
Questions 21

A breakpoint is added to a saved playbook to ensure that it pauses before running the task "ad-delete-user." However, it is later discovered that an Active Directory account was deleted by this playbook, and the playbook did not pause at the breakpoint.

What is the cause of this issue?.

Options:

A.

The playbook does not stop at the breakpoint when run from an incident.

B.

The task was not set to "skip.".

C.

The task was not configured to override input.

D.

The playbook was not set to "quiet mode.".

Buy Now
Questions 22

Where is a custom layout for an incident configured?.

Options:

A.

Pre-process rule.

B.

Incident playbook.

C.

Integration instance settings.

D.

Incident type.

Buy Now
Questions 23

What is the most effective way to correlate multiple raw events coming from a SIEM and link them together?

Options:

A.

Process all alerts by running the respective playbook and link related incidents during post-processing

B.

Ingest all raw events, run a custom script to find the relationship between them and proceed to link them together

C.

Configure a pre-process rule to link related events as they are ingested

D.

Manually go through the incidents created by the raw events and link related incidents

Buy Now
Questions 24

When creating an incident layout section, it is best to place long field values within which of the following?

Options:

A.

Section headers

B.

Rows

C.

Canvas

D.

Cards

Buy Now
Questions 25

Which two behaviors occur while an incident is closed? (Choose two.).

Options:

A.

Playbook is marked as complete.

B.

Commands cannot be executed in the War Room.

C.

Timers can no longer run.

D.

Running timers are in a paused state.

Buy Now
Questions 26

What determines the current verdict for an indicator when multiple sources provide different reliability scores and verdicts?.

Options:

A.

Verdict provided by the most recently updated source.

B.

Average verdict score from all sources.

C.

Verdict provided by the source with the highest reliability score.

D.

Highest severity verdict from all sources.

Buy Now
Questions 27

A large number of incidents were deleted by mistake.

Which two architecture components can be used to recover the lost data? (Choose two.)

Options:

A.

Live backup

B.

Engine

C.

Distributed database

D.

Local backup

Buy Now
Questions 28

Which two functions in XSOAR are incident types used for? (Choose two.)

Options:

A.

To run dedicated playbooks for different event types

B.

To classify events ingested from various sources into the relevant types

C.

To classify indicators extracted in XSOAR incidents to their respective types

D.

To facilitate role based access to XSOAR incidents

Buy Now
Questions 29

Management would like to get an incident report automatically following an incident’s closure. How would this be accomplished?

Options:

A.

Define a task in a playbook to generate an incident report before the closure occurs

B.

Manually create an ‘Incident Report’

C.

Configure post-processing using a script

D.

Create an ‘Incident Report’ from the Reports page

Buy Now
Questions 30

Which Marketplace content pack will allow sharing of threat intelligence in STIX format?.

Options:

A.

External dynamic list.

B.

MISP Server.

C.

Generic Export Indicators Service.

D.

TAXII Server.

Buy Now
Questions 31

What are the out-of-the-box aggregate values that can be applied on widgets data?

Options:

A.

Min, Max, Count, Average, Custom Transformers

B.

Min, Max, Count, Average, Custom Group By

C.

Count, Average, Sum, Min, Max

D.

Count, Sum, Min, Max, Transformers

Buy Now
Questions 32

An engineer deployed two different instances of Active Directory for each organization site. As part of account enrichment use case, the engineer would like to delete a user from one specific site.

Which command will accomplish this?

Options:

A.

run ‘ad-delete-user’ command with ‘user-dn’ arg and using-brand=“Active Directory Query v2”

B.

run ‘ad-delete-user’ command with ‘user-dn’ arg and raw-response=true

C.

run ‘ad-delete-user’ command with ‘user-dn’ arg and ignore-outputs=true

D.

run ‘ad-delete-user’ command with ‘user-dn’ arg and using=“Active DirectoryQuery v2_instance_1”

Buy Now
Questions 33

After executing the DeleteContext automation with all=yes argument, how would the context data of an incident present?

Options:

A.

All the data, including the incident key will be deleted, and the context data will be completely empty.

B.

No difference, the automation cannot be executed manually.

C.

All context data, including custom incident fields will be deleted, system incident fields will remain.

D.

All context data, except the incident key will be deleted.

Buy Now
Questions 34

An organization has recently acquired another company as its subsidiary. The subsidiary has its infrastructure on AWS cloud as illustrated in the image below:

XSOAR-Engineer Question 34

The organization wants to use the mail server location on the subsidiary's cloud to send emails. Without acquiring additional licenses, which XSOAR component can fulfill the requirement?

Options:

A.

XSOAR D2 Agents, to send the required emails.

B.

An XSOAR engine that is downloaded from the XSOAR server and installed within the subsidiary.

C.

Another XSOAR server that uses the same license as their primary XSOAR server.

D.

A Linux server connected with an XSOAR server using SSH integration. Commands can be run remotely to access the mail server.

Buy Now
Questions 35

Which XSOAR architecture would be recommended for Managed Security Service Providers (MSSP)?

Options:

A.

Multi-region

B.

Dev-Prod

C.

Multi-tenant

D.

Distributed database

Buy Now
Questions 36

Within the playbook editor, which function allows a user to associate a task output to an incident field?.

Options:

A.

Classification.

B.

Inputs.

C.

Extend context.

D.

Mapping.

Buy Now
Questions 37

Which of the following is a feature of XSOAR automations?

Options:

A.

can run on multiple docker containers

B.

can be set to run on a scheduled basis in the automation settings

C.

can be password protected

D.

can be written in C++

Buy Now
Questions 38

Which of these would be the most operationally efficient repository for moving XSOAR custom content from a development server to a production environment?

Options:

A.

A content repository specified in the Marketplace

B.

Remote git repository specified in the dev-prod configuration parameters

C.

The development server's default repository

D.

Cortex XSOAR public content repository

Buy Now
Questions 39

Incidents need to be filtered by all of the following criteria:

1.Status – Pending

2.Exclude Category – Job

3.Severity – High

4.Owner – None (No owner assigned)

5.Type – Phishing

6.Email Subject – “You have won a million dollars”

What is the correct query syntax for the above incident search filter?

Options:

A.

status==“Pending“andandcategory!=”job”andandseverity==”High”andandowner==”None”andandtype==”Phishing”andandemailsubject==”You have won a million dollars”

B.

Status:Pending and –Category:job and Severity:High and Owner:”” and Type:Phishing and Email Subject:You have won a million dollars

C.

status:Pending and –category:job and severity:High and owner:”” and type:Phishing and emailsubject:”You have won a million dollars”

D.

status:Pending or –category:job or severity:High or owner:”” or type:Phishing or emailsubject:”You have won a million dollars”

Buy Now
Questions 40

Where does the mapping of user groups to SAML groups take place?.

Options:

A.

Cortex Gateway.

B.

Tenant.

C.

Customer Support Portal.

D.

Palo Alto Networks Hub.

Buy Now
Questions 41

Which two solutions are available to scale an overloaded XSOAR environment? (Choose two.)

Options:

A.

Add a distributed database server

B.

Add an indexing server

C.

Add a live backup server (disaster recovery)

D.

Add an engine

Buy Now
Questions 42

An incident field is created having the display name as Source_IP. How can the field be accessed?

Options:

A.

${incident.sourceip}

B.

${incident.Source_IP}

C.

${incident.srcip}

D.

${incident.Source IP}

Buy Now
Questions 43

When the "Only allow these dashboards" checkbox is selected for a user role, what is the primary effect on users assigned this role?.

Options:

A.

They are prompted to select their preferred dashboards upon login and can only modify these chosen dashboards.

B.

They can only view specified dashboards and make minor modifications.

C.

They will automatically have all dashboards that are shared with them added to their view.

D.

They will be restricted to viewing only the specified default dashboards and cannot make any modifications.

Buy Now
Questions 44

An engineer creates a script to display data in markdown format for a layout. When configuring the layout, the new script is not listed.

Which missed configuration step will cause this behavior?.

Options:

A.

Tagging the script with Dynamic Section.

B.

Ensuring the script has the necessary permissions.

C.

Adding the snippet as an integration command.

D.

Using a markdown output type.

Buy Now
Questions 45

An Engineer wants to filter a csvList value according to a dynamic value saved under the test context key.

Which three values would save the test context key? (Choose three.)

Options:

A.

Get csvList.value where csvList.value equals test [from previous tasks]

B.

Get csvList.value where csvList.value equals ${test} [from previous tasks]

C.

Get csvList.value where csvList.value equals test {}[from previous tasks]

D.

Get csvList.value where csvList.value equals test [as value]

E.

Get csvList.value where csvList.value equals ${test} [as value]

Buy Now
Questions 46

A SOC analyst needs to retrieve the list of all open phishing incidents in the last 30 days. What is the correct query to use?

Options:

A.

-status:closed -category:job type:Phishing created:>="30 days ago"

B.

status:closed -category:jobandtype:Phishing created:>="30 days ago"

C.

-status:closed -category:jobandtype:Phishing created:<="30 days ago"

D.

-status:closed -category:job type:Phishing created:="30 days ago"

Buy Now
Questions 47

What assigns newly ingested event attributes to incident fields?

Options:

A.

Playbooks

B.

Classification

C.

Mapping

D.

Layouts

Buy Now
Questions 48

Reliability scores in XSOAR range from A through F. What do A and F stand for?

Options:

A.

F - Reliability cannot be judged, A - Completely Reliable

B.

F - Not reliable, A - Usually Reliable

C.

F - Not usually reliable, A - Fairly Reliable

D.

F - Unreliable, A - Completely Reliable

Buy Now
Questions 49

Match the corresponding action with the appropriate playbook tasks.

XSOAR-Engineer Question 49

Options:

Buy Now
Questions 50

A playbook needs to dynamically add an email sender's address to a Cortex XSOAR list named "BlockedSenders_Email."

Which built-in command should be used within the playbook to add this email address to the specified list?.

Options:

A.

!addToList listName="BlockedSenders_Email" listData="".

B.

!appendToListContext listPath="BlockedSenders Email" data="".

C.

!setIncident list.BlockedSenders_Emai1="".

D.

!createListItem listName="BlockedSenders_Email" itemValue="".

Buy Now
Questions 51

Based on the image below, which key from the context points to the string GOGL?.

XSOAR-Engineer Question 51

Options:

A.

Whois.IP.asn_registry.entities.

B.

Whois.IP.[0].network.name.

C.

Whois.IP.network.name.

D.

Whois.IP.entities.

Buy Now
Questions 52

What happens if both a Classifier and Incident Type are configured in an integration instance's settings?

Options:

A.

The administrator will receive a notification that there is both a Classifier and Incident Type set for that integration instance.

B.

The Incident Type will be ignored, and incoming incidents will be classified according to the Classifier.

C.

The Classifier will be ignored, and incoming incidents will be classified according to the Incident Type.

D.

Both the Classifier and Incident Type will classify incoming incidents.

Buy Now
Questions 53

Select the correct incident life cycle on XSOAR.

Options:

A.

Planning > Incident Ingestion > Incident Creation > Mapping and Classification > Pre-processing > Playbook runs > Post-processing

B.

Planning > Incident Ingestion > Pre-processing > Incident Creation > Mapping and Classification > Playbook runs > Post-processing

C.

Planning > Incident Ingestion > Pre-processing > Mapping and Classification > Incident Creation > Playbook runs > Post-processing

D.

Planning > Incident Ingestion > Mapping and Classification > Pre-processing > Incident Creation > Playbook runs > Post-processing

Buy Now
Questions 54

How would context data be filtered to receive only malicious indicator values with DBotScore?

Options:

A.

Get DBotScore.value where DBotScore.Score (Larger or equals) 4

B.

Get DBotScore.value where DBotScore.Score (equals (int)) 3

C.

Get DBotScore where DBotScore.Score (Larger than) 1

D.

Get DBotScore where DBotScore.Score (Larger or equals) 2

Buy Now
Questions 55

Match the action with the most appropriate playbook task type.

XSOAR-Engineer Question 55

Options:

Buy Now
Questions 56

When mapping incoming data to incident fields, which statement is correct?

Options:

A.

Data that is not mapped is placed under labels

B.

Only text fields are classified

C.

Classification cannot be used if mapping is enabled

D.

Every incoming field must be mapped

Buy Now
Questions 57

How is data transferred between playbook tasks?

Options:

A.

Read/Write from context data

B.

Over war room results

C.

Input from the indicator page

D.

Directly from a previous task

Buy Now
Questions 58

An engineer would like to add a custom field to the New Job form for a job triggered from a threat intel feed. How would the engineer implement this?

Options:

A.

The new job form changes based on the threat intel feed integration configuration

B.

The new job form can be edited from the Indicator Feed incident type editor

C.

The new job form for a threat intel feed job cannot be edited

D.

The new job form can be edited from the threat intel feeds integration settings

Buy Now
Questions 59

What is an outcome of using sections within a tab when customizing an incident layout?.

Options:

A.

Triggering specific automations or playbooks when data within that section is modified during an investigation.

B.

Enforcing mandatory fields that must be completed before an incident can be closed.

C.

Grouping related fields and information logically, improving readability and data entry efficiency.

D.

Restricting access to sensitive fields based on user roles, ensuring data privacy within the specific incident type.

Buy Now
Questions 60

Which of the following is a basic setting that can be configured in an automation?

Options:

A.

Summary

B.

Compiler

C.

Schedule

D.

Run On

Buy Now
Questions 61

Which two causes may be occurring if an integration test is working, but the integration is not fetching incidents? (Choose two.)

Options:

A.

The ’Fetches Incidents’ option may not have been enabled

B.

There are no new events from the external service

C.

The first fetch should be manually triggered to start the fetching process

D.

It can take up to 1-hour before incidents are initially fetched

Buy Now
Exam Code: XSOAR-Engineer
Exam Name: Palo Alto Networks XSOAR Engineer
Last Update: Dec 13, 2025
Questions: 204

PDF + Testing Engine

$63.52  $181.49

Testing Engine

$50.57  $144.49
buy now XSOAR-Engineer testing engine

PDF (Q&A)

$43.57  $124.49
buy now XSOAR-Engineer pdf