Palo Alto Networks XSOAR Engineer - XSOAR-Engineer Exam Practice Test
What are two of the actions available on the Version History tab of a content pack in the marketplace?
(Choose two.)
(Choose two.)
Correct Answer: B,C
What is the difference between labels and fields?
Correct Answer: D
Incidents need to be filtered by all of the following criteria:
1.Status - Pending
2.Exclude Category - Job
3.Severity - High
4.Owner - None (No owner assigned)
5.Type - Phishing
6.Email Subject - "You have won a million dollars"
What is the correct query syntax for the above incident search filter?
1.Status - Pending
2.Exclude Category - Job
3.Severity - High
4.Owner - None (No owner assigned)
5.Type - Phishing
6.Email Subject - "You have won a million dollars"
What is the correct query syntax for the above incident search filter?
Correct Answer: C
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
Given an incident with three files, how could the name of the second file be referenced?
Correct Answer: B
The default expiration method for non-feed indicators is either to never expire or to expire after a specific period of time. How frequently does XSOAR check tor newly expired indicators?
Correct Answer: A
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
Which two methods are used to add new content to the XSOAR Content Repository? (Choose two.)
Correct Answer: B,D
What are two common use cases for conditional tasks? (Choose two.)
Correct Answer: B,D
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
Which option is available in XSOAR to create the body of a Threat Intel Report?
Correct Answer: D
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
Which three support types are included in the Marketplace Content Packs? (Choose three.)
Correct Answer: A,B,E
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
How would context data be filtered to receive only malicious indicator values with DBotScore?
Correct Answer: D
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
An engineer asked for a specific command in an integration but the capability does not exist. The engineer decided to edit the existing integration by copying the integration and adding the needed commands.
What is the main concern when adding these commands?
What is the main concern when adding these commands?
Correct Answer: D
Which investigation element is best suited for collaboration among users?
Correct Answer: B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
Match the action with the most appropriate playbook task type.


Correct Answer:

Explanation:

https://www.jaacostan.com/2021/02/palo-alto-cortex-xsoar-playbook-icons.html
Which XSOAR architecture would be recommended for Managed Security Service Providers (MSSP)?
Correct Answer: B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).