Free Palo Alto Networks XSOAR-Engineer Exam Questions (page: 3)

Which two methods will allow data to be saved in incident fields within a playbook? (Choose two.)

  1. setFields
  2. Field mapping
  3. setIncident
  4. Layout inline editing

Answer(s): B,C



DRAG DROP (Drag and Drop is not supported)

Match the action with the most appropriate playbook task type.

  1. See Explanation for the Answer.

Answer(s): A

Explanation:



https://www.jaacostan.com/2021/02/palo-alto-cortex-xsoar-playbook-icons.html



Which built-in automation/command cab be used to change an incident's type?

  1. setIncident
  2. Set
  3. GetFieldsByIncidentType
  4. modifyIncidentFields

Answer(s): A


Reference:

https://docs.paloaltonetworks.com/cortex/cortex-xsoar/5-5/cortex-xsoar- admin/incidents/incidents- management/incident-fields/field-trigger-scripts.html



An engineer notices that playbooks only start once the user clicks the `investigate' button and he/she would like the playbook to start automatically.

How can this be implemented?

  1. Add the playbook to the integration's settings
  2. Select `Run playbook automatically' from the incident type settings
  3. Add the !startinvestigation automation to the beginning of the playbook
  4. Select `Run playbook automatically' from the integration settings

Answer(s): B



Which two causes may be occurring if an integration test is working, but the integration is not fetching incidents? (Choose two.)

  1. The 'Fetches Incidents' option may not have been enabled
  2. There are no new events from the external service
  3. The first fetch should be manually triggered to start the fetching process
  4. It can take up to 1-hour before incidents are initially fetched

Answer(s): A,B



Viewing page 3 of 33
Viewing questions 11 - 15 out of 156 questions



Post your Comments and Discuss Palo Alto Networks XSOAR-Engineer exam prep with other Community members:

XSOAR-Engineer Exam Discussions & Posts