New Year Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Paloalto Networks XSOAR-Engineer Practice Exam with Questions & Answers

Questions 1

When creating an incident layout section, it is best to place long field values within which of the following?

Options:
A.

Section headers

B.

Rows

C.

Canvas

D.

Cards

Questions 2

After executing the DeleteContext automation with all=yes argument, how would the context data of an incident present?

Options:
A.

All the data, including the incident key will be deleted, and the context data will be completely empty.

B.

No difference, the automation cannot be executed manually.

C.

All context data, including custom incident fields will be deleted, system incident fields will remain.

D.

All context data, except the incident key will be deleted.

Questions 3

What is the most effective way to correlate multiple raw events coming from a SIEM and link them together?

Options:
A.

Process all alerts by running the respective playbook and link related incidents during post-processing

B.

Ingest all raw events, run a custom script to find the relationship between them and proceed to link them together

C.

Configure a pre-process rule to link related events as they are ingested

D.

Manually go through the incidents created by the raw events and link related incidents

Questions 4

How long is the trial period for paid content packs?

Options:
A.

30 days

B.

14 days

C.

7 days

D.

60 days

Questions 5

While testing a custom integration, an XSOAR engineer noticed that the incident fetch interval is missing. How can this be fixed?

Options:
A.

Define the Incident Fetch Interval when running the integration’s commands.

B.

Duplicate the integration. Edit the resulting copy and add incidentFetchInterval as a parameter. Save the integration. Configure the new integration instance with the interval required.

C.

Configure the application to send incidents on the required interval.

D.

Duplicate the integration. Add the interval in the code. Save the integration and Configure the new integration instance with the interval required.

Questions 6

Match the action with the most appropriate playbook task type.

XSOAR-Engineer Question 6

Options:
Questions 7

When browsing the Marketplace for new content packs, which details about each pack are you able to view?

Options:
A.

The integration’s source code

B.

A summary of each version history

C.

A test instance for the content pack

D.

The source code of each playbook

Questions 8

Where do you navigate to monitor and improve the system performance and resilience for hosts in a multitenant environment?

Options:
A.

Settings > About > Troubleshooting, in the main host account. Each host has a System Diagnostics page.

B.

Settings > Advanced > System Diagnostics, in the main host account. Each host has a System Diagnostics page.

C.

Settings > Account Management > Hosts, in the main host account. Each host has a System Diagnostics page.

D.

Settings > About > System Diagnostics, in the main host account. Each host has a System Diagnostics page.

Questions 9

If a known malicious domain is no longer associated with a specific IP address, which action will make the association inactive?.

Options:
A.

Revoke the relationship.

B.

Update the relationship type.

C.

Expire the IP address indicator.

D.

Update the indicator relationship description.

Questions 10

What does the outgoing mapper support?

Options:
A.

Mirroring

B.

Classification

C.

Dynamic fields

D.

Pre-processing