New Year Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Paloalto Networks XSOAR-Engineer Practice Exam with Questions & Answers | Set: 4

Questions 31

After enriching a username using Active Directory, an engineer would like to send an email to the user’s manager. However, this functionality is not part of the command output. The engineer checks with raw- response=true and notices that the manager’s email is returned, but not saved in the context.

How can the engineer save the data so it will be accessible?

Options:
A.

Mark ignore output = true

B.

Use extend-context

C.

Use raw-response = save

D.

Mark ignore input = true

Paloalto Networks XSOAR-Engineer Premium Access
Questions 32

To avoid exceeding API quotas for third-party services, indicators are only updated after the indicator cache expiration period. What is the default cache expiration period for indicators in XSOAR (minutes/days)?

Options:
A.

10,080 minutes (7 days)

B.

20,160 minutes (14 days)

C.

21,600 minutes (15 days)

D.

4,320 minutes (3 days)

Questions 33

XSOAR-Engineer Question 33

Given the following context data, what would be the expected output of the expression?

Options:
A.

1E56733826E5035233A097FCEA2046AF96EC616C

B.

E6EF5142E2553C1E442A0FFAC07636EAC61E6EDD

C.

8D193FA162A305E4859BA8C45F5121F7265E3ABB

D.

e6ef5142e2553c1e442a0ffac07636eac61e6edd

Questions 34

Which two advanced attributes can be applied to incident fields when editing? (Choose two.)

Options:
A.

Set a field trigger script

B.

Associate to an incident type

C.

Change field type

D.

Change field name

Questions 35

Which component can be part of a load balancing group?

Options:
A.

Distributed database

B.

D2 agent

C.

Engine

D.

Load balancing server

Questions 36

In order to automatically run a playbook on the indicators fetched by an integration, what would an XSOAR Administrator setup?

Options:
A.

Cron job

B.

Time triggered job

C.

Feed triggered job

D.

REST API job

Questions 37

An engineer notices that playbooks only start once the user clicks the ‘investigate’ button and he/she would like the playbook to start automatically.

How can this be implemented?

Options:
A.

Add the playbook to the integration’s settings

B.

Select ‘Run playbook automatically’ from the incident type settings

C.

Add the !startinvestigation automation to the beginning of the playbook

D.

Select ‘Run playbook automatically’ from the integration settings

Questions 38

Which two capabilities do Automation script settings include? (Choose two.)

Options:
A.

Define ‘parameters’

B.

Correlate to incident types

C.

Define ‘outputs’

D.

Set password protection

Questions 39

Which three authentication methods are supported when logging into XSOAR? (Choose three.)

Options:
A.

OTP token

B.

User name and password

C.

SAML

D.

Active Directory authentication

E.

RADIUS

Questions 40

What is the correct definition regarding integration parameters and command arguments?

Options:
A.

Parameters are global variables which means that every command can use these configurable options in order to run. Arguments are shared with other commands and must be present for each command.

B.

Parameters are local variables which means that every command can use these configurable options in order to run. Arguments are shared with other commands and must be present for each command.

C.

Parameters are local variables which means that every command can use these configurable options in order to run. Arguments are specific to only one command.

D.

Parameters are global variables which means that every command can use these configurable options in order to run. Arguments are specific to only one command.