
Palo Alto NetworksCertified XSOAR Engineer
Domain 5Objective 7
5.7 Demonstrate Understanding of Indicator Exclusions List Configuration and Management XSOAR-ENGINEER Practice Questions (Page 4)
Part of the Threat Intelligence Management domain, which accounts for 18% of the XSOAR-ENGINEER exam.
19questions here
4free pages
4concepts
18%of the exam
Questions 16–19
- 16
An administrator needs to add a large list of known safe file hashes to the indicator exclusions list. The list is in a CSV file with columns 'hash' and 'comment'. What is the most efficient way to add these hashes to the exclusions list?
Select an answer first - 17
A security analyst added a domain to the indicator exclusions list six months ago because it was used by a marketing campaign. The campaign has ended, and the domain is now being used for malicious activity. The analyst needs to ensure that this domain is no longer excluded and can be processed normally. What should the analyst do?
Select an answer first - 18
What is the primary purpose of an indicator exclusions list in XSOAR?
Select an answer first - 19
In XSOAR, which of the following is a valid setting when adding an indicator to the exclusions list?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to XSOAR-ENGINEER
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XSOAR-ENGINEER” is a trademark of its owner, used for identification only.