ExamDumpster

Free XSOAR-ENGINEER sample questions

Real questions from the Palo Alto Networks Certified XSOAR Engineer practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 10 of 20 free sample questions.

Question 1Choose one

An organization requires a Cortex XSOAR engine to be deployed in a restricted network zone (DMZ) to facilitate integration with internal security tools that cannot be exposed directly to the internet. The XSOAR main server is hosted in the cloud. Which connection method must be configured on the engine to ensure secure communication with the main server?

Question 2Choose one

A SOC Engineer needs to migrate custom content (playbooks, scripts, and layouts) from a Development XSOAR environment to a Production environment. The organization enforces strict version control and peer review processes. What is the recommended method to achieve this migration?

Question 3Choose one

You are troubleshooting a failed integration fetch in Cortex XSOAR. The integration connects to an external SIEM to pull alerts. The error log shows 'CertificateVerifyFailed'. The SIEM uses a self-signed certificate. How should you resolve this issue securely while maintaining the integration?

Question 4Choose one

True or False: When a Content Pack update is available in the Marketplace, updating it will automatically overwrite any local changes made to the out-of-the-box playbooks included in that pack, without creating a backup.

Question 5Choose 2

An engineer needs to optimize the database storage of a Cortex XSOAR environment. Which TWO actions can effectively reduce the disk space consumed by incidents and indicators? (Select TWO)

Question 6Choose one

A security engineer is configuring a new classifier for email-based incidents. The requirement is to classify emails with the subject 'Phishing Alert' as 'Phishing' incidents, and emails with 'Malware Detected' as 'Malware' incidents. All other emails should be classified as 'General'. Which configuration step is essential to achieve this?

Question 7Choose one

You are mapping a JSON alert from a SIEM to XSOAR fields. The JSON structure contains a nested field: `{"alert": {"details": {"source_ip": "192.168.1.1"}}}`. Which syntax correctly extracts the IP address in the Mapper configuration?

Question 8Choose one

A layout for the 'Phishing' incident type must show a specific tab called 'Forensics' ONLY if the incident severity is 'High' or 'Critical'. How should this be configured?

Question 9Choose one

You are creating a custom Incident Type 'Malware Investigation'. You want to ensure that whenever an incident of this type is created, a specific playbook 'Malware Response v2' is automatically assigned and executed. Where do you configure this association?

Question 10Choose one

A developer needs to store a list of malicious IP addresses that are updated daily by an external threat feed. This list will be used by multiple playbooks to block traffic. Which Cortex XSOAR feature is best suited for storing and managing this data?

10 more free samples are waiting

Create a free account to unlock the whole XSOAR-ENGINEER sample bank, or get full access to all 210 practice questions in the simulator.

Create account