Palo Alto Networks XSOAR Engineer Questions and Answers
Which three scripting languages can an engineer use to write XSOAR automations? (Choose three.)
Which two causes may be occurring if an integration test is working, but the integration is not fetching incidents? (Choose two.)
Which command adds or updates a description to an incident that can be used within widgets?
Which command adds or updates a description to an incident that can be used within widgets?.
Within the playbook editor, which function allows a user to associate a task output to an incident field?.
Which tag must be applied to an Automation Script in order for it to be available when configuring an Indicator Type?
An Engineer wants to filter a csvList value according to a dynamic value saved under the test context key.
Which three values would save the test context key? (Choose three.)
What is used to trigger playbooks automatically based on the classification of an incident?
Previous playbook tasks have built out the context in the image below.

When specifying ${User.Name} as an input for a sub playbook task which has the default loop configuration, how many times will the sub-playbook be executed?.
An administrator has noticed that an integration has failed to fetch incidents. Where would they go to download logs to troubleshoot the error?
What can be added to offload integration instance processing from the main server?
Which of the following are valid methods to contribute custom content? (Choose three.)
What aggregates data from incidents and indicators into a Cortex XSOAR report?.
Which two functions in XSOAR are incident types used for? (Choose two.)
An engineer notices that playbooks only start once the user clicks the ‘investigate’ button and he/she would like the playbook to start automatically.
How can this be implemented?
What is the result of an indicator being marked as expired?.
Which two features does XSOAR offer to help recover from a server failure? (Choose two.)
Threat Intel search queries can be shared with which of the following? (Select 1)
What are two main uses of context data? (Choose two.)
Which two input requirements are needed to train a machine learning model? (Choose two.)
During configuration of the inputs of a sub-playbook in the main playbook, there is an option under the Loop tab called "For Each Input". What is this option used to?
An administrator wants to run an automation in the War Room to set the incident field "Description" to "Confirmed Phishing". Which command should they enter in the War Room CLI?
Which development languages are supported when creating XSOAR automation scripts?
A SOC analyst needs to retrieve the list of all open phishing incidents in the last 30 days. What is the correct query to use?
When developing the playbook, which of the following can be used by a XSOAR Administrator?
Which two behaviors occur while an incident is closed? (Choose two.).
A playbook task generates a report as HTML in the context data.
An engineer creates a custom indicator field of type "HTML" and adds the field to a section in a custom indicator layout. How can the engineer populate the HTML field in the indicator layout?
What is a primary use case of data collection tasks?
Match the corresponding action with the appropriate playbook tasks.

An administrator wants to send an email via the Mail Sender integration. Which of the following out of the box methods would be used for that?
An analyst wants to run a script to remove usernames from an incident before the incident becomes active in XSOAR. How can this be achieved?
Which three statements are true about the Marketplace? (Choose three.)
What is the most effective way to correlate multiple raw events coming from a SIEM and link them together?
Where do you navigate to monitor and improve the system performance and resilience for hosts in a multitenant environment?
Which two actions will group similar incidents that share a common root cause or represent different aspects of a larger problem? (Choose two.).
An incident field is created having the display name as Source_IP. How can the field be accessed?
How would context data be filtered to receive only malicious indicator values with DBotScore?
An XSOAR Engineer has developed a playbook and would like to contribute it to the XSOAR Marketplace to share with other users.
Which two options are available to the Engineer for contributing to the Marketplace? (Choose two.)
A breakpoint is added to a saved playbook to ensure that it pauses before running the task "ad-delete-user." However, it is later discovered that an Active Directory account was deleted by this playbook, and the playbook did not pause at the breakpoint.
What is the cause of this issue?.
How can Cortex XSOAR administrators prevent junior analysts from viewing a senior analyst dashboard?
Which three authentication methods are supported when logging into XSOAR? (Choose three.)
An incident has been created in the following state:
There is no playbook attached.
The War Room is available, but no commands have been run yet.
What is the status of the incident?.
Which feature is used to convert event data values into incident fields when an integration fetches an event?.
What happens if both a Classifier and Incident Type are configured in an integration instance's settings?
An engineer is developing a playbook that will be run multiple times for testing purposes. What is the recommended first task to be used in the playbook?
In which two locations can filters and transformers be used in XSOAR? (Choose two.)
On the System Diagnostics page, what is the default minimum size for a Work Plan to be considered big?
When creating a new tab in the layout, which section cannot be added?
What is the default configuration for indicator auto-extraction when incidents are created?
A playbook needs to dynamically add an email sender's address to a Cortex XSOAR list named "BlockedSenders_Email."
Which built-in command should be used within the playbook to add this email address to the specified list?.
What are three different loop types in a playbook? (Choose three.)
During the regular maintenance of XSOAR a customer noticed that there was an update available for the Active Directory content pack (current version 1.4.6) and updated the content pack to the latest version (version 1.4.11). However, after the update the customer noticed that the Active Directory Query integration is not working properly and asked you to resolve the issue.
Which of the following set of steps can help to resolve the issue?
When the "Only allow these dashboards" checkbox is selected for a user role, what is the primary effect on users assigned this role?.
What does the outgoing mapper support?
Which two options will troubleshoot an integration’s fetch incidents command? (Choose two.)
When creating an incident layout section, it is best to place long field values within which of the following?
How long is the trial period for paid content packs?
When is the post-processing script executed in XSOAR?
An engineer creates a script to display data in markdown format for a layout. When configuring the layout, the new script is not listed.
Which missed configuration step will cause this behavior?.
An engineer would like to present a trend using widgets to compare to a previous week’s data. Which two methods will allow the engineer to meet the requirement? (Choose two.)
Based on the image below, what could be the reason for this behavior?.

Which two advanced attributes can be applied to incident fields when editing? (Choose two.)
