A temporary integration issue causes a scheduled job to fail continuously.
Which action will ensure the job continues to run after future failures?.
Which two methods will allow data to be saved in incident fields within a playbook? (Choose two.)
An incident field is created having the display name as Source_IP. How can the field be accessed?
Which of the following are valid methods to contribute custom content? (Choose three.)
An engineer defined a dashboard which allows important metrics to be displayed. The engineer would like to make this dashboard the default dashboard.
How can it be accomplished?
An engineer creates a script to display data in markdown format for a layout. When configuring the layout, the new script is not listed.
Which missed configuration step will cause this behavior?.
Inside the Incidents table view, which actions can be performed on the selected incidents? (Choose two.)
An engineer wants to save a command output to a custom context key using "Extend Context" in a playbook task. To do this, the engineer needs the full context path of the command's output.
Which common CLI argument or flag can help identify this full output and its correct path?.
What is the default configuration for indicator auto-extraction when incidents are created?
Which two options may be added when a content pack is being installed? (Choose two.)
Which feature is used to convert event data values into incident fields when an integration fetches an event?.
In which two locations can filters and transformers be used in XSOAR? (Choose two.)
An administrator wants to run an automation in the War Room to set the incident field "Description" to "Confirmed Phishing". Which command should they enter in the War Room CLI?
Which three scripting languages can an engineer use to write XSOAR automations? (Choose three.)
When creating an incident layout section, it is best to place long field values within which of the following?
Which two actions will group similar incidents that share a common root cause or represent different aspects of a larger problem? (Choose two.).
What determines the current verdict for an indicator when multiple sources provide different reliability scores and verdicts?.
An analyst wants to run a script to remove usernames from an incident before the incident becomes active in XSOAR. How can this be achieved?
A Cortex XSOAR Administrator is tasked with building a button for an analyst in order for the analyst to be assigned to the incident as an owner. What is the process?
What is an outcome of using sections within a tab when customizing an incident layout?.
You can customize most aspects of the incident layout, including which three of the following? (Choose three.)
Which set of trigger options is available to start a job when a new instance is created?.
Two feed integrations with the same source reliability (B - Usually reliable) fetch the same indicator with the following verdicts:
Integration A - Malicious
Integration B - Benign
Indicator data from Integration B was fetched after Integration A.
What will be the values of the fields associated with the indicator?.
Which two features does XSOAR offer to help recover from a server failure? (Choose two.)
What are the out-of-the-box aggregate values that can be applied on widgets data?
In which two scenarios would it be appropriate to implement a loop for a sub-playbook? (Choose two.)
An Engineer wants to filter a csvList value according to a dynamic value saved under the test context key.
Which three values would save the test context key? (Choose three.)
Which two input requirements are needed to train a machine learning model? (Choose two.)
Which tag must be applied to an Automation Script in order for it to be available when configuring an Indicator Type?
What is the correct definition regarding integration parameters and command arguments?
On the System Diagnostics page, what is the default minimum size for a Work Plan to be considered big?
What can you use to assign a layout, field, and playbook to an incoming incident?
A breakpoint is added to a saved playbook to ensure that it pauses before running the task "ad-delete-user." However, it is later discovered that an Active Directory account was deleted by this playbook, and the playbook did not pause at the breakpoint.
What is the cause of this issue?.
What is used to trigger playbooks automatically based on the classification of an incident?
When re-assigning an existing incident to a new incident type, an engineer is concerned about the preservation of critical data currently stored in fields that are only associated to the original incident type.
Upon making the change, in which state will the critical data be in the now unassociated fields?.
Which option is available in XSOAR to create the body of a Threat Intel Report?
When the verdict of an indicator is set manually, which source reliability does it receive?.
Given an incident with three files, how could the name of the second file be referenced?
How can Cortex XSOAR administrators prevent junior analysts from viewing a senior analyst dashboard?
What aggregates data from incidents and indicators into a Cortex XSOAR report?.
A SOC team must send a notification email to specific teams based on the severity of an incident.
Which feature will accomplish this task each time the severity escalates?.
The XSOAR administrator is writing an automation and would like to return an error entry back into XSOAR if a particular command errors out. How can this be achieved?
An engineer’s organization system is registered in the following manner:
What is the most efficient way for the engineer to achieve this?
An administrator has noticed that an integration has failed to fetch incidents. Where would they go to download logs to troubleshoot the error?
A playbook task generates a report as HTML in the context data.
An engineer creates a custom indicator field of type "HTML" and adds the field to a section in a custom indicator layout. How can the engineer populate the HTML field in the indicator layout?