XSOAR-Engineer Palo Alto Networks XSOAR Engineer Questions and Answers
Which three scripting languages can an engineer use to write XSOAR automations? (Choose three.)
Which three authentication methods are supported when logging into XSOAR? (Choose three.)
Which set of trigger options is available to start a job when a new instance is created?.
An engineer defined a dashboard which allows important metrics to be displayed. The engineer would like to make this dashboard the default dashboard.
How can it be accomplished?
Which of the following does a XSOAR Admin need to create an integration with a third party cloud application?
What happens if both a Classifier and Incident Type are configured in an integration instance's settings?
Which action will resolve the issue when an analyst upgrades a content pack from the Marketplace, and the new version has a code error?.
An engineer creates a script to display data in markdown format for a layout. When configuring the layout, the new script is not listed.
Which missed configuration step will cause this behavior?.
Which three support types are included in the Marketplace Content Packs? (Choose three.)
An engineer notices that playbooks only start once the user clicks the ‘investigate’ button and he/she would like the playbook to start automatically.
How can this be implemented?
An engineer would like to add a custom field to the New Job form for a job triggered from a threat intel feed. How would the engineer implement this?
When the "Only allow these dashboards" checkbox is selected for a user role, what is the primary effect on users assigned this role?.
What is the correct definition regarding integration parameters and command arguments?
What can you use to assign a layout, field, and playbook to an incoming incident?
An engineer adds a new "Forensics" tab that includes several sections for detailed artifact analysis to the "Malware Incident" layout. However, junior analysts report they cannot see this tab, while senior analysts can.
Which configuration setting is the most likely reason for this discrepancy?.
In which two ways can data be transferred between playbooks and sub-playbooks? (Choose two.)
An analyst runs the following command in a playbook task:
!ip ip=1.1.1.1
Which extraction mode needs to be enabled on the Advanced tab of the playbook task to synchronously extract indicators from the results of this command?
What is an outcome of using sections within a tab when customizing an incident layout?.
What determines the current verdict for an indicator when multiple sources provide different reliability scores and verdicts?.
Previous playbook tasks have built out the context in the image below.

When specifying ${User.Name} as an input for a sub playbook task which has the default loop configuration, how many times will the sub-playbook be executed?.
What aggregates data from incidents and indicators into a Cortex XSOAR report?.
Where would you look to find a personalized view of your own incidents and tasks?
Which field type should be used to hold more than 60,000 characters of unformatted text?
When uploading content, which two options could the upload include? (Choose two.)
Which two input requirements are needed to train a machine learning model? (Choose two.)
What are two of the actions available on the Version History tab of a content pack in the marketplace? (Choose two.)
In which two locations can filters and transformers be used in XSOAR? (Choose two.)
Inside the Incidents table view, which actions can be performed on the selected incidents? (Choose two.)
Which XSOAR architecture would be recommended for Managed Security Service Providers (MSSP)?
When using the playbook debugger, what may be the cause of a starred incident missing from the Test Data selections?.
An engineer’s organization system is registered in the following manner:
What is the most efficient way for the engineer to achieve this?
An engineer wants to customize the regex for the default IP indicator type. How can this change be implemented?
Which two options may be added when a content pack is being installed? (Choose two.)
An XSOAR Engineer has developed a playbook and would like to contribute it to the XSOAR Marketplace to share with other users.
Which two options are available to the Engineer for contributing to the Marketplace? (Choose two.)
What is used to trigger playbooks automatically based on the classification of an incident?
When re-assigning an existing incident to a new incident type, an engineer is concerned about the preservation of critical data currently stored in fields that are only associated to the original incident type.
Upon making the change, in which state will the critical data be in the now unassociated fields?.
An engineer asked for a specific command in an integration but the capability does not exist. The engineer decided to edit the existing integration by copying the integration and adding the needed commands.
What is the main concern when adding these commands?
When creating an automation in XSOAR, what is the best way to create a log message?
A SOC analyst needs to retrieve the list of all open phishing incidents in the last 30 days. What is the correct query to use?
After executing the DeleteContext automation with all=yes argument, how would the context data of an incident present?
An administrator has noticed that an incident fetch has failed, causing several internal workflows to be backed up. The administrator would like to receive notifications the next time the incident fetch fails.
How can they achieve this?






