New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Paloalto Networks Security Operations XSOAR-Engineer Questions and answers with CertsForce

Viewing page 1 out of 7 pages
Viewing questions 1-10 out of questions
Questions # 1:

A playbook loop that interacts with Active Directory for user details (yielding extensive data) is altered to extract newly acquired indicators of compromise (IOCs). This change results in two critical issues:

• Rate limits being hit on integrated reputation services

• Incidents associated with hundreds of indicators

Given the settings below, what would prevent the issues in this use case?

Incident Type: AD-Analysis –

Extract Indicators on Incident Creation: Use System Default (None)

Extract Indicators on Field Change: Inline

Task 1: ad-get-user –

Mark results as note: False –

Indicator Extract Mode: Inline –

Quiet Mode: False –

Task 2: ad-disable-account –

Mark results as note: True –

Indicator Extract Mode: None –

Quiet Mode: True –

Task 3: servicenow-update-ticket –

Mark results as note: False –

Indicator Extract Mode: Use System Default

Quiet Mode: False

Options:

A.

Set AD-Analysis incident creation extraction to "Extract specific indicators.”


B.

Set ad-get-user indicator extraction mode to None.


C.

Set servicenow-update-ticket indicator extraction mode to Inline.


D.

Disable the feature that allows marking task outputs as notes.


Expert Solution
Questions # 2:

What is the primary effect on a new file hash when it is added to the indicator exclusion list?.

Options:

A.

It is not extracted, enriched, or given a new verdict.


B.

It is extracted and stored, but an "exclusion" tag is added, requiring manual review before it can affect any incidents.


C.

It is processed normally by enrichment automations, but the verdict is set to "benign.".


D.

It is excluded from intelligence feeds that have a reliability score lower than "B - Usually reliable.".


Expert Solution
Questions # 3:

What happens if both a Classifier and Incident Type are configured in an integration instance's settings?

Options:

A.

The administrator will receive a notification that there is both a Classifier and Incident Type set for that integration instance.


B.

The Incident Type will be ignored, and incoming incidents will be classified according to the Classifier.


C.

The Classifier will be ignored, and incoming incidents will be classified according to the Incident Type.


D.

Both the Classifier and Incident Type will classify incoming incidents.


Expert Solution
Questions # 4:

A playbook task generates a report as HTML in the context data.

An engineer creates a custom indicator field of type "HTML" and adds the field to a section in a custom indicator layout. How can the engineer populate the HTML field in the indicator layout?

Options:

A.

Populate the custom indicator field with the built-in !SetIndicator command.


B.

Add HTML to a list using !setList and use it as an HTML template to populate the custom indicator field.


C.

Create a custom Indicator Mapper and populate the custom indicator field.


D.

Use the Mapping option in the playbook task that generates the HTML report to populate the custom indicator field.


Expert Solution
Questions # 5:

What is the function of timer SLA fields in Cortex XSOAR?

Options:

A.

To track SLA breaches per playbook


B.

To run a script that executes on SLA assignment


C.

To automatically alert the analyst on SLA breach


D.

To count the time between one or more tasks


Expert Solution
Questions # 6:

Which field type provides an interactive and editable display of table-based data?

Options:

A.

HTML


B.

Grid (table)


C.

Markdown


D.

Multi Select


Expert Solution
Questions # 7:

Which component can be part of a load balancing group?

Options:

A.

Distributed database


B.

D2 agent


C.

Engine


D.

Load balancing server


Expert Solution
Questions # 8:

Which XSOAR architecture would be recommended for Managed Security Service Providers (MSSP)?

Options:

A.

Multi-region


B.

Dev-Prod


C.

Multi-tenant


D.

Distributed database


Expert Solution
Questions # 9:

An organization has recently acquired another company as its subsidiary. The subsidiary has its infrastructure on AWS cloud as illustrated in the image below:

Question # 9

The organization wants to use the mail server location on the subsidiary's cloud to send emails. Without acquiring additional licenses, which XSOAR component can fulfill the requirement?

Options:

A.

XSOAR D2 Agents, to send the required emails.


B.

An XSOAR engine that is downloaded from the XSOAR server and installed within the subsidiary.


C.

Another XSOAR server that uses the same license as their primary XSOAR server.


D.

A Linux server connected with an XSOAR server using SSH integration. Commands can be run remotely to access the mail server.


Expert Solution
Questions # 10:

Where does the mapping of user groups to SAML groups take place?.

Options:

A.

Cortex Gateway.


B.

Tenant.


C.

Customer Support Portal.


D.

Palo Alto Networks Hub.


Expert Solution
Viewing page 1 out of 7 pages
Viewing questions 1-10 out of questions