New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Paloalto Networks Security Operations XSOAR-Engineer Questions and answers with CertsForce

Viewing page 6 out of 7 pages
Viewing questions 51-60 out of questions
Questions # 51:

What are three different loop types in a playbook? (Choose three.)

Options:

A.

Automation


B.

Built-in


C.

Data collection


D.

Conditional


E.

For-each


Expert Solution
Questions # 52:

Which feature is used to convert event data values into incident fields when an integration fetches an event?.

Options:

A.

Classification.


B.

Mapping.


C.

Field configuration.


D.

Layout configuration.


Expert Solution
Questions # 53:

Which set of trigger options is available to start a job when a new instance is created?.

Options:

A.

"Mapping" and "Classification"


B.

"Time" and "By delta in feed"


C.

"Cron View" and "Human View"


D.

"Script Start" and "CLI"


Expert Solution
Questions # 54:

An engineer deployed two different instances of Active Directory for each organization site. As part of account enrichment use case, the engineer would like to delete a user from one specific site.

Which command will accomplish this?

Options:

A.

run ‘ad-delete-user’ command with ‘user-dn’ arg and using-brand=“Active Directory Query v2”


B.

run ‘ad-delete-user’ command with ‘user-dn’ arg and raw-response=true


C.

run ‘ad-delete-user’ command with ‘user-dn’ arg and ignore-outputs=true


D.

run ‘ad-delete-user’ command with ‘user-dn’ arg and using=“Active DirectoryQuery v2_instance_1”


Expert Solution
Questions # 55:

After executing the DeleteContext automation with all=yes argument, how would the context data of an incident present?

Options:

A.

All the data, including the incident key will be deleted, and the context data will be completely empty.


B.

No difference, the automation cannot be executed manually.


C.

All context data, including custom incident fields will be deleted, system incident fields will remain.


D.

All context data, except the incident key will be deleted.


Expert Solution
Questions # 56:

Arrange these steps in the order that they occur during an incident fetch.

Question # 56


Expert Solution
Questions # 57:

Which two functions in XSOAR are incident types used for? (Choose two.)

Options:

A.

To run dedicated playbooks for different event types


B.

To classify events ingested from various sources into the relevant types


C.

To classify indicators extracted in XSOAR incidents to their respective types


D.

To facilitate role based access to XSOAR incidents


Expert Solution
Questions # 58:

You need to retrieve a list of all malicious hashes over the last 30 days. What is the correct query to use?

Options:

A.

type:File reputation:Malicious sourcetimestamp:"30 days ago"


B.

type:File verdict:Malicious sourcetimestamp:<="30 days ago"


C.

type:File reputation:Malicious sourcetimestamp:="30 days ago"


D.

type:File verdict:Malicious sourcetimestamp:>="30 days ago"


Expert Solution
Questions # 59:

When creating an incident layout section, it is best to place long field values within which of the following?

Options:

A.

Section headers


B.

Rows


C.

Canvas


D.

Cards


Expert Solution
Questions # 60:

An engineer wants to save a command output to a custom context key using "Extend Context" in a playbook task. To do this, the engineer needs the full context path of the command's output.

Which common CLI argument or flag can help identify this full output and its correct path?.

Options:

A.

debug-mode.


B.

auto extract.


C.

raw-response.


D.

extend-parent-context.


Expert Solution
Viewing page 6 out of 7 pages
Viewing questions 51-60 out of questions