
Palo Alto NetworksCertified XSOAR Engineer
Domain 4Objective 1
4.1 Explain Incident States and Actions XSOAR-ENGINEER Practice Questions (Page 3)
Part of the Incident Interactions and Reporting domain, which accounts for 16% of the XSOAR-ENGINEER exam.
21questions here
5free pages
4concepts
16%of the exam
Questions 11–15
- 11
An XSOAR administrator is configuring an incident type where an incident should automatically transition from 'New' to 'In Progress' when a specific playbook starts. However, the administrator notices that the playbook is not changing the state as expected. What is the most likely reason for this?
Select an answer first - 12
A security analyst is working on an incident that was closed prematurely by an automated playbook. After reviewing the evidence, the analyst determines the incident requires further investigation. Which action should the analyst take to continue working on the incident?
Select an answer first - 13
Which incident state in Cortex XSOAR is typically used to indicate that the underlying issue has been addressed but the incident record has not yet been formally closed?
Select an answer first - 14
A security analyst has completed the investigation of an incident and wants to ensure that the incident is no longer visible in the active incident list. The analyst also wants to preserve the incident data for future reference. Which action should the analyst take?
Select an answer first - 15
An XSOAR administrator is designing a workflow where an incident must go through a 'Pending Review' state before it can be closed. The administrator notices that the default incident states do not include 'Pending Review'. What is the most effective way to implement this requirement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “XSOAR-ENGINEER” is a trademark of its owner, used for identification only.