PCSAE Practice Test Questions

156 Questions


Which three actions can an engineer take on the troubleshooting page? (Choose three.)


A. Download the debug log bundle


B. Put the XSOAR server in maintenance mode


C. View and modify server configuration settings


D. Export and import custom content


E. View a list of server administrators





A.
  Download the debug log bundle

B.
  Put the XSOAR server in maintenance mode

C.
  View and modify server configuration settings

Which three authentication methods are supported when logging into XSOAR? (Choose three.)


A. OTP token


B. User name and password


C. SAML


D. Active Directory authentication


E. RADIUS





C.
  SAML

D.
  Active Directory authentication

E.
  RADIUS

Inside the Incidents table view, which actions can be performed on the selected incidents? (Choose two.)


A. Run Command, Export, and Close and Delete for all selected incidents regardless of their status


B. Assign, Edit, and Mark as Duplicate for all selected incidents regardless of their status


C. Run Command for all selected incidents having Active status


D. Export incidents as JSON and change incident status





A.
  Run Command, Export, and Close and Delete for all selected incidents regardless of their status

B.
  Assign, Edit, and Mark as Duplicate for all selected incidents regardless of their status

Which three types of information are displayed on the incident Quick View? (Choose three.)


A. Indicators and relationships


B. Timeline information


C. Evidence Board


D. Context data


E. Incident severity





A.
  Indicators and relationships

B.
  Timeline information

C.
  Evidence Board

What does Script helper contain?


A. Available commands


B. Permission settings


C. Automation version history


D. Automation timeout configuration





A.
  Available commands

In which three locations can an engineer try to find information, when troubleshooting a failed integration instance error produced by the test button? (Choose three.)


A. The audit log


B. The log bundle


C. The source code for an integration


D. The error message returned directly below the button


E. The playground war room





B.
  The log bundle

C.
  The source code for an integration

D.
  The error message returned directly below the button

What is a primary use case of data collection tasks?


A. To allow multi-QUESTION NO: surveys without authentication restrictions


B. To automate tasks such as parsing a file or enriching indicators


C. To generate new widgets for a dashboard


D. To determine different paths in a playbook





A.
  To allow multi-QUESTION NO: surveys without authentication restrictions

The default expiration method for non-feed indicators is either to never expire or to expire after a specific period of time. How frequently does XSOAR check tor newly expired indicators?


A. Every 24 hours


B. Every 5 minutes


C. Every 8 hours


D. Every 1 hour





D.
  Every 1 hour

Which of these would be the most operationally efficient repository for moving XSOAR custom content from a development server to a production environment?


A. A content repository specified in the Marketplace


B. Remote git repository specified in the dev-prod configuration parameters


C. The development server's default repository


D. Cortex XSOAR public content repository





B.
  Remote git repository specified in the dev-prod configuration parameters

A SOC manager built a dashboard and would like to share the dashboard with other team members. How would the SOC manager create a dashboard that meets this requirement?


A. Manually share the dashboard through user emails


B. Dashboard is shared to all XSOAR users


C. Propagate the dashboard based on SAML authentication


D. Dashboard is shared to all XSOAR users in a selected role





D.
  Dashboard is shared to all XSOAR users in a selected role

Where would you look to find a personalized view of your own incidents and tasks?


A. Incident Summary View


B. My Incidents


C. My Threat Landscape


D. My Dashboard





D.
  My Dashboard

Which three options can be defined in the layout settings? (Choose three.)


A. Set of fields to present


B. Permission to view the tab based on ‘Users’


C. Permission to view the tab based on ‘Roles’


D. Delete built-in tabs including the war room


E. Dynamic sections





A.
  Set of fields to present

C.
  Permission to view the tab based on ‘Roles’

E.
  Dynamic sections


Page 5 out of 13 Pages
Previous