XSOAR-Engineer試験無料問題集「Palo Alto Networks XSOAR Engineer 認定」

How long is the trial period for paid content packs?

解説: (GoShiken メンバーにのみ表示されます)
A playbook loop that interacts with Active Directory for user details (yielding extensive data) is altered to extract newly acquired indicators of compromise (IOCs). This change results in two critical issues:
* Rate limits being hit on integrated reputation services
* Incidents associated with hundreds of indicators
Given the settings below, what would prevent the issues in this use case?
Incident Type: AD-Analysis -
Extract Indicators on Incident Creation: Use System Default (None)
Extract Indicators on Field Change: Inline
Task 1: ad-get-user -
Mark results as note: False -
Indicator Extract Mode: Inline -
Quiet Mode: False -
Task 2: ad-disable-account -
Mark results as note: True -
Indicator Extract Mode: None -
Quiet Mode: True -
Task 3: servicenow-update-ticket -
Mark results as note: False -
Indicator Extract Mode: Use System Default
Quiet Mode: False

解説: (GoShiken メンバーにのみ表示されます)
Which two capabilities do Automation script settings include? (Choose two.)

In order to automatically run a playbook on the indicators fetched by an integration, what would an XSOAR Administrator setup?

解説: (GoShiken メンバーにのみ表示されます)
Assuming an incident type configuration runs the associated playbook automatically, which pre-process rule action can preserve matching incidents without triggering the playbook?.

解説: (GoShiken メンバーにのみ表示されます)
Which configuration is a valid distributed database (DB) implementation?

Which of the following are valid methods to contribute custom content? (Choose three.)

正解:C,D,E 解答を投票する
Where can engineers add the post-processing scripts to incidents?

Which two reasons would lead an engineer to create a custom widget? (Choose two.)

解説: (GoShiken メンバーにのみ表示されます)
Within the playbook editor, which function allows a user to associate a task output to an incident field?.

解説: (GoShiken メンバーにのみ表示されます)
What happens if both a Classifier and Incident Type are configured in an integration instance's settings?