Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Palo Alto Networks XSOAR Engineer XSOAR-Engineer Exam Questions

Page: 1 / 14 Total 204 questions

Want more questions? Get Premium Access.

Question 1

An engineer adds a new "Forensics" tab that includes several sections for detailed artifact analysis to the "Malware Incident" layout. However, junior analysts report they cannot see this tab, while senior analysts can.

Which configuration setting is the most likely reason for this discrepancy?.

Correct Answer: B. The tab was not added to the junior analyst role group.
Explanation:

According to the Cortex XSOAR Admin Guide, visibility of layout tabs is controlled by role-based access permissions (RBAC). When customizing layouts, administrators can assign tabs, fields, and components to specific user roles. If the ''Forensics'' tab appears for senior analysts but not junior analysts, this indicates that the tab has been assigned only to certain roles through the ''Roles'' field in the layout editor.

XSOAR does not hide layout tabs due to incorrect field mappings (option A). If a field is unmapped, it simply appears empty, not invisible. Likewise, marking a tab as ''read-only'' (option C) still makes it visible; it only restricts editing. Display filters (option D) apply to list widgets, dashboards, and incidents---not layout tab visibility.

The documentation clearly states that a tab will not appear to a user unless their assigned role is included in the tab's role permissions. Therefore, junior analysts cannot view the tab because the tab was not assigned to their role, making option B the correct explanation based on XSOAR's RBAC-controlled layout behavior.


Question 2

When developing the playbook, which of the following can be used by a XSOAR Administrator?

Correct Answer: C. Debugger panel and XML data from a similar incident with New Mock Incident. This will not affect the incidents original incident data.

Question 3

What are two main uses of context data? (Choose two.)

Correct Answer: A. Store incident information in JSON format; C. Pass data between playbook tasks

Question 4

Which feature is used to convert event data values into incident fields when an integration fetches an event?.

Correct Answer: B. Mapping.
Explanation:

XSOAR's ingestion pipeline defines a strict order in which raw fetched data is processed, and the Admin Guide explains that Classification determines the incident type based on incoming fields, while Mapping performs the actual transformation of event data into structured incident fields. Mapping profiles define how each field from the integration's raw JSON (for example, source_ip, username, alert_id) is converted into standard or custom incident fields.

The Mapping Editor allows administrators to select specific fields from the incoming event data and bind them to incident fields used throughout playbooks, layouts, and reports. This ensures normalization of data and consistent schema usage across the SOC.

The documentation makes clear that Mapping is responsible for populating incident field values, whereas Classification only chooses the incident type. Field configuration defines field metadata but does not map values. Layout configuration controls visual presentation only and does not populate fields.

Thus, option B (Mapping) is the function that converts event data into incident field values and is the correct answer according to the ingestion architecture documented in the XSOAR Admin Guide.


Question 5

The code snippet below is from the fetch command of an integration instance configured to run on the server.

demisto.debug(f"(len(incidents)} events fetched")

Where is the output from the snippet located when the instance runs an automatic fetch?.

Correct Answer: C. Integration Logs table.
Explanation:

Integration debug messages (generated using demisto.debug) are stored in the Integration Logs table, not in the War Room or incident labels.

The Admin Guide states that all logs generated by integration code are visible through the Integration Logs section for troubleshooting.


Question 6

What are inputs and outputs in reference to a Playbook Development Lifecycle? (Choose three.)

Correct Answer: A. Inputs are data pieces that are present in the playbook; D. Outputs can be derived from the result of a task or command; E. Inputs are the data fields parsed by the Classifier

Question 7

What are two of the actions available on the Version History tab of a content pack in the marketplace? (Choose two.)

Correct Answer: C. Update to x version; D. Revert to x version

Question 8

Which two functions in XSOAR are incident types used for? (Choose two.)

Correct Answer: B. To classify events ingested from various sources into the relevant types; C. To classify indicators extracted in XSOAR incidents to their respective types

Question 9

When is the post-processing script executed in XSOAR?

Correct Answer: C. Just after the playbook is executed

Question 10

Within the playbook editor, which function allows a user to associate a task output to an incident field?.

Correct Answer: C. Extend context.
Explanation:

The XSOAR Playbook Editor allows engineers to manipulate and transform context data dynamically. According to the XSOAR Admin and Playbook Development Guides, ''Extend Context'' is the dedicated mechanism that enables a task to save output values into new or existing context keys, including keys that correspond to incident fields. By defining a key under the ''Extend Context'' section, the playbook task can map specific outputs---such as JSON fields, strings, arrays, or nested objects---to a structured location within the incident context. These keys can then be used to populate incident fields through further playbook tasks, field mappings, or automated incident field updates.

Classification (option A) applies only during ingestion and cannot assign task outputs to incident fields. Inputs (option B) define what data a task receives, not how it is stored afterward. Mapping (option D) belongs to the ingestion pipeline and determines how event fields become incident fields during creation, not during playbook execution.

Therefore, Extend Context is the correct feature that allows a task to associate its output with incident fields, making option C the correct answer based on documentation.


Question 11

An analyst runs the following command in a playbook task:

!ip ip=1.1.1.1

Which extraction mode needs to be enabled on the Advanced tab of the playbook task to synchronously extract indicators from the results of this command?

Correct Answer: D. Inline

Question 12

In which two options can an automation script be executed? (Choose two.)

Correct Answer: C. War room; D. Playbook

Question 13

In which three locations can an engineer try to find information, when troubleshooting a failed integration instance error produced by the test button? (Choose three.)

Correct Answer: B. The log bundle; C. The source code for an integration; D. The error message returned directly below the button

Question 14

An administrator has noticed that an integration has failed to fetch incidents. Where would they go to download logs to troubleshoot the error?

Correct Answer: B. Settings > About > Troubleshooting > Set Log Level to Debug > Download Logs

Question 15

Which three support types are included in the Marketplace Content Packs? (Choose three.)

Correct Answer: B. Contex XSOAR supported; C. Community supported; D. Partner supported