New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Paloalto Networks Palo Alto Networks XSOAR Engineer XSOAR-Engineer Question # 1 Topic 1 Discussion

Paloalto Networks Palo Alto Networks XSOAR Engineer XSOAR-Engineer Question # 1 Topic 1 Discussion

XSOAR-Engineer Exam Topic 1 Question 1 Discussion:
Question #: 1
Topic #: 1

A playbook loop that interacts with Active Directory for user details (yielding extensive data) is altered to extract newly acquired indicators of compromise (IOCs). This change results in two critical issues:

• Rate limits being hit on integrated reputation services

• Incidents associated with hundreds of indicators

Given the settings below, what would prevent the issues in this use case?

Incident Type: AD-Analysis –

Extract Indicators on Incident Creation: Use System Default (None)

Extract Indicators on Field Change: Inline

Task 1: ad-get-user –

Mark results as note: False –

Indicator Extract Mode: Inline –

Quiet Mode: False –

Task 2: ad-disable-account –

Mark results as note: True –

Indicator Extract Mode: None –

Quiet Mode: True –

Task 3: servicenow-update-ticket –

Mark results as note: False –

Indicator Extract Mode: Use System Default

Quiet Mode: False


A.

Set AD-Analysis incident creation extraction to "Extract specific indicators.”


B.

Set ad-get-user indicator extraction mode to None.


C.

Set servicenow-update-ticket indicator extraction mode to Inline.


D.

Disable the feature that allows marking task outputs as notes.


Get Premium XSOAR-Engineer Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.