New Year Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

An incident field is created having the display name as Source_IP. How can the field be accessed?

A.

${incident.sourceip}

B.

${incident.Source_IP}

C.

${incident.srcip}

D.

${incident.Source IP}

Which two features can be used together to automatically execute a search on a remote SIEM for extracted IP Indicators? (Choose two.).

A.

Reputation script.

B.

Enhancement script.

C.

Integration command.

D.

Feed-triggered job.

An analyst wants to run a script to remove usernames from an incident before the incident becomes active in XSOAR. How can this be achieved?

A.

Run an automation script in the Playground to remove usernames from the incident.

B.

Create a pre-processing rule that runs an automation script to remove usernames from the incident as it comes into XSOAR.

C.

Run an automation script on the XSOAR server to remove usernames from the incident.

D.

Create a playbook task to remove the usernames from the incident.

Where is a custom layout for an incident configured?.

A.

Pre-process rule.

B.

Incident playbook.

C.

Integration instance settings.

D.

Incident type.

Which of the following does a XSOAR Admin need to create an integration with a third party cloud application?

A.

Marketplace access

B.

Application with API

C.

Private key/Public key integration

D.

Multitenant deployment

What aggregates data from incidents and indicators into a Cortex XSOAR report?.

A.

Widgets.

B.

Automations.

C.

SQL queries.

D.

Playbooks.

What are the three ways to add/mark entries as evidence inside the Evidence Board? (Choose three.)

A.

Manually directly from the War Room with the Actions drop-down

B.

From the Notes section (mark as entry icon)

C.

Manually from the playbook task (mark as entry icon)

D.

Automatically from playbook tasks when the option is selected on the Advanced tab

E.

By running the command !MarkAsEvidence

Which investigation element is best suited for collaboration among users?

A.

Work Plan

B.

Related Incidents

C.

War Room

D.

Context Data

What is an example of a generic reputation command?

A.

!ip

B.

!getReputation

C.

!reputation

D.

!enrichIndicator

Which three support types are included in the Marketplace Content Packs? (Choose three.)

A.

Customer supported

B.

Contex XSOAR supported

C.

Community supported

D.

Partner supported

E.

Prisma Cloud supported