Incidents need to be filtered by all of the following criteria:
1.Status – Pending
2.Exclude Category – Job
3.Severity – High
4.Owner – None (No owner assigned)
5.Type – Phishing
6.Email Subject – “You have won a million dollars”
What is the correct query syntax for the above incident search filter?
Which two features does XSOAR offer to help recover from a server failure? (Choose two.)
Which two situations would an engineer consider when configuring classification and mapping for an incident type? (Choose two.)
A Cortex XSOAR Administrator is tasked with building a button for an analyst in order for the analyst to be assigned to the incident as an owner. What is the process?
A playbook task generates a report as HTML in the context data.
An engineer creates a custom indicator field of type "HTML" and adds the field to a section in a custom indicator layout. How can the engineer populate the HTML field in the indicator layout?
A SOC manager built a dashboard and would like to share the dashboard with other team members. How would the SOC manager create a dashboard that meets this requirement?
What assigns newly ingested event attributes to incident fields?
Which field type provides an interactive and editable display of table-based data?
What is the default configuration for indicator auto-extraction when incidents are created?
Arrange these steps in the order that they occur during an incident fetch.
Which investigation element is best suited for collaboration among users?
What is used to trigger playbooks automatically based on the classification of an incident?
Given the following context data, what would be the expected output of the expression?
What does the outgoing mapper support?
An administrator wants to send an email via the Mail Sender integration. Which of the following out of the box methods would be used for that?
What is the most effective way to correlate multiple raw events coming from a SIEM and link them together?
An engineer notices that playbooks only start once the user clicks the ‘investigate’ button and he/she would like the playbook to start automatically.
How can this be implemented?
Which of the following is a basic setting that can be configured in an automation?
An engineer would like to change an incident’s SLA according to the severity field changes. How can the engineer achieve this task?
Match the corresponding action with the appropriate playbook tasks.
Which three statements are true about the Marketplace? (Choose three.)
Which two options may be added when a content pack is being installed? (Choose two.)
When creating a new tab in the layout, which section cannot be added?