Which two advanced attributes can be applied to incident fields when editing? (Choose two.)
Which two functions in XSOAR are incident types used for? (Choose two.)
Which two features does XSOAR offer to help recover from a server failure? (Choose two.)
Two feed integrations with the same source reliability (B - Usually reliable) fetch the same indicator with the following verdicts:
Integration A - Malicious
Integration B - Benign
Indicator data from Integration B was fetched after Integration A.
What will be the values of the fields associated with the indicator?.
An XSOAR Engineer has developed a playbook and would like to contribute it to the XSOAR Marketplace to share with other users.
Which two options are available to the Engineer for contributing to the Marketplace? (Choose two.)
Arrange these steps in the order that they occur during an incident fetch.

An engineer creates a script to display data in markdown format for a layout. When configuring the layout, the new script is not listed.
Which missed configuration step will cause this behavior?.
Which field type provides an interactive and editable display of table-based data?
By default, automation written in which language will be executed in a Docker container?
What are two common use cases for conditional tasks? (Choose two.)
What are inputs and outputs in reference to a Playbook Development Lifecycle? (Choose three.)
Which three statements are true about the Marketplace? (Choose three.)
What is needed to send a survey with multiple questions to a customer?.
For troubleshooting, after a log bundle is created, where do the logs appear on the XCSOAR server?
In Cortex XSOAR multi tenant setup, when content from a development server is pushed to the remote repository, where in the production server can the updates be found?
What is the default task type when creating an empty task?
An administrator has noticed that an incident fetch has failed, causing several internal workflows to be backed up. The administrator would like to receive notifications the next time the incident fetch fails.
How can they achieve this?
A SOC manager built a dashboard and would like to share the dashboard with other team members. How would the SOC manager create a dashboard that meets this requirement?
Which two input requirements are needed to train a machine learning model? (Choose two.)
Which two causes may be occurring if an integration test is working, but the integration is not fetching incidents? (Choose two.)
What is used to trigger playbooks automatically based on the classification of an incident?
What are the three ways to add/mark entries as evidence inside the Evidence Board? (Choose three.)
Which playbook will a job run by default?
Where is a custom layout for an incident configured?.
Which of the following are valid methods to contribute custom content? (Choose three.)
A temporary integration issue causes a scheduled job to fail continuously.
Which action will ensure the job continues to run after future failures?.
Whar are possible war room result (entry) types?
What is the default landing page for a new user in XSOAR?
What is the correct way to install different engines on the same Ubuntu machine for a Dev/Prod setup?.
Which component can be part of a load balancing group?
Which development languages are supported when creating XSOAR automation scripts?
What is the most effective way to correlate multiple raw events coming from a SIEM and link them together?
A breakpoint is added to a saved playbook to ensure that it pauses before running the task "ad-delete-user." However, it is later discovered that an Active Directory account was deleted by this playbook, and the playbook did not pause at the breakpoint.
What is the cause of this issue?.
In which two options can an automation script be executed? (Choose two.)
Which Marketplace content pack will allow sharing of threat intelligence in STIX format?.
Which of the following is a basic setting that can be configured in an automation?
Inside the Incidents table view, which actions can be performed on the selected incidents? (Choose two.)
What is the result of an indicator being marked as expired?.
An engineer must create a playbook task which asks a user a single question to determine the next step in the playbook flow.
Which type of task will accomplish this goal?.
In which two locations can filters and transformers be used in XSOAR? (Choose two.)
What must happen before a pre-process rule can be applied to a potential incident?.
A Cortex XSOAR Administrator is tasked with building a button for an analyst in order for the analyst to be assigned to the incident as an owner. What is the process?
Incidents need to be filtered by all of the following criteria:
1.Status – Pending
2.Exclude Category – Job
3.Severity – High
4.Owner – None (No owner assigned)
5.Type – Phishing
6.Email Subject – “You have won a million dollars”
What is the correct query syntax for the above incident search filter?
Previous playbook tasks have built out the context in the image below.

When specifying ${User.Name} as an input for a sub playbook task which has the default loop configuration, how many times will the sub-playbook be executed?.
Which two options may be added when a content pack is being installed? (Choose two.)
What can be used as integration parameters?
What are two of the actions available on the Version History tab of a content pack in the marketplace? (Choose two.)
What is an example of a generic reputation command?
In which two scenarios would it be appropriate to implement a loop for a sub-playbook? (Choose two.)
You need to retrieve a list of all malicious hashes over the last 30 days. What is the correct query to use?
How is data transferred between playbook tasks?
Which two capabilities do Automation script settings include? (Choose two.)
An Engineer wants to filter a csvList value according to a dynamic value saved under the test context key.
Which three values would save the test context key? (Choose three.)
Which XSOAR architecture would be recommended for Managed Security Service Providers (MSSP)?
During configuration of the inputs of a sub-playbook in the main playbook, there is an option under the Loop tab called "For Each Input". What is this option used to?
Which of these would be the most operationally efficient repository for moving XSOAR custom content from a development server to a production environment?
What is the primary effect on a new file hash when it is added to the indicator exclusion list?.
An engineer wants to customize the regex for the default IP indicator type. How can this change be implemented?
Which two situations would an engineer consider when configuring classification and mapping for an incident type? (Choose two.)
The default expiration method for non-feed indicators is either to never expire or to expire after a specific period of time. How frequently does XSOAR check tor newly expired indicators?
What is the default configuration for indicator auto-extraction when incidents are created?