What is the function of timer SLA fields in Cortex XSOAR?
An incident field is created having the display name as Source_IP. How can the field be accessed?
In which two scenarios would it be appropriate to implement a loop for a sub-playbook? (Choose two.)
An XSOAR Engineer has developed a playbook and would like to contribute it to the XSOAR Marketplace to share with other users.
Which two options are available to the Engineer for contributing to the Marketplace? (Choose two.)
To avoid exceeding API quotas for third-party services, indicators are only updated after the indicator cache expiration period. What is the default cache expiration period for indicators in XSOAR (minutes/days)?
Which tag must be applied to an Automation Script in order for it to be available when configuring an Indicator Type?
Threat Intel search queries can be shared with which of the following? (Select 1)
An engineer asked for a specific command in an integration but the capability does not exist. The engineer decided to edit the existing integration by copying the integration and adding the needed commands.
What is the main concern when adding these commands?
When developing the playbook, which of the following can be used by a XSOAR Administrator?
An engineer’s organization system is registered in the following manner:
What is the most efficient way for the engineer to achieve this?
What will happen if a playbook debugger is left running for more than 24 hours?
An administrator wants to run an automation in the War Room to set the incident field "Description" to "Confirmed Phishing". Which command should they enter in the War Room CLI?
By default, which components does an XSOAR implementation include?
Which two functions in XSOAR are incident types used for? (Choose two.)
What happens if both a Classifier and Incident Type are configured in an integration instance's settings?
When uploading content, which two options could the upload include? (Choose two.)
Inside the Incidents table view, which actions can be performed on the selected incidents? (Choose two.)
Which field type should be used to hold more than 60,000 characters of unformatted text?
How is data transferred between playbook tasks?
How would context data be filtered to receive only malicious indicator values with DBotScore?
What are two common use cases for conditional tasks? (Choose two.)
Which task type would be used to verify/check that an integration was enabled?
At what stage during the incident lifecycle is an incident type assigned?