Palo Alto Networks Certified XSOAR Engineer Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 210 questions. Use the simulator for timed and flashcard mode.

Try Simulator

XSOAR-ENGINEER Sample Questions

  1. Question 1

    Q1

    An organization requires a Cortex XSOAR engine to be deployed in a restricted network zone (DMZ) to facilitate integration with internal security tools that cannot be exposed directly to the internet. The XSOAR main server is hosted in the cloud. Which connection method must be configured on the engine to ensure secure communication with the main server?

    Show answer & explanation

    Correct answer: B

    Cortex XSOAR engines are designed to initiate the connection to the main server. They establish a persistent HTTPS (WebSocket) tunnel outbound on port 443. This design allows engines to sit behind firewalls without requiring inbound ports to be opened.

  2. Question 2

    Q2

    A SOC Engineer needs to migrate custom content (playbooks, scripts, and layouts) from a Development XSOAR environment to a Production environment. The organization enforces strict version control and peer review processes. What is the recommended method to achieve this migration?

    Show answer & explanation

    Correct answer: B

    The Remote Repository feature allows XSOAR to integrate directly with Git. The recommended workflow for strict version control is to push content from the Development environment to a Git repository branch, perform peer reviews/merges, and then pull the approved content into the Production environment.

  3. Question 3

    Q3

    You are troubleshooting a failed integration fetch in Cortex XSOAR. The integration connects to an external SIEM to pull alerts. The error log shows 'CertificateVerifyFailed'. The SIEM uses a self-signed certificate. How should you resolve this issue securely while maintaining the integration?

    Show answer & explanation

    Correct answer: B

    The most secure method is to import the self-signed certificate (or the signing CA) into the trust store used by the integration (often within the Docker container or the host engine). Simply trusting 'any' certificate is a security risk and not recommended for production.

  4. Question 4

    Q4

    True or False: When a Content Pack update is available in the Marketplace, updating it will automatically overwrite any local changes made to the out-of-the-box playbooks included in that pack, without creating a backup.

    Show answer & explanation

    Correct answer: B

    False. Cortex XSOAR prevents overwriting detached content. If you have modified an out-of-the-box playbook, it becomes 'detached'. You must either reattach it (losing changes) or duplicate it before updating. Generally, it is best practice to detach or duplicate content before editing to avoid update conflicts.

  5. Question 5

    Q5Multiple answers

    An engineer needs to optimize the database storage of a Cortex XSOAR environment. Which TWO actions can effectively reduce the disk space consumed by incidents and indicators? (Select TWO)

    Show answer & explanation

    Correct answers: A, C

    Reducing the retention period allows the system to prune older data, freeing up significant disk space.

    Preprocessing rules prevent unnecessary data from ever entering the database, which is a proactive way to manage storage growth.

  6. Question 6

    Q6

    A security engineer is configuring a new classifier for email-based incidents. The requirement is to classify emails with the subject 'Phishing Alert' as 'Phishing' incidents, and emails with 'Malware Detected' as 'Malware' incidents. All other emails should be classified as 'General'. Which configuration step is essential to achieve this?

    Show answer & explanation

    Correct answer: A

    The classifier evaluates rules. If a rule matches 'Phishing Alert', it sets the type. If no rules match, the system uses the Default Incident Type configured in the integration or classifier settings.

  7. Question 7

    Q7

    You are mapping a JSON alert from a SIEM to XSOAR fields. The JSON structure contains a nested field: {"alert": {"details": {"source_ip": "192.168.1.1"}}}. Which syntax correctly extracts the IP address in the Mapper configuration?

    Show answer & explanation

    Correct answer: A

    In XSOAR Mappers, dot notation is used to traverse nested JSON objects to extract specific values.

  8. Question 8

    Q8

    A layout for the 'Phishing' incident type must show a specific tab called 'Forensics' ONLY if the incident severity is 'High' or 'Critical'. How should this be configured?

    Show answer & explanation

    Correct answer: B

    Tabs and sections in layouts can have display conditions configured directly in the Layout Editor. These conditions can check field values like 'severity' to determine visibility.

  9. Question 9

    Q9

    You are creating a custom Incident Type 'Malware Investigation'. You want to ensure that whenever an incident of this type is created, a specific playbook 'Malware Response v2' is automatically assigned and executed. Where do you configure this association?

    Show answer & explanation

    Correct answer: B

    The association between an Incident Type and its default playbook is defined in the Incident Type configuration page.

  10. Question 10

    Q10

    A developer needs to store a list of malicious IP addresses that are updated daily by an external threat feed. This list will be used by multiple playbooks to block traffic. Which Cortex XSOAR feature is best suited for storing and managing this data?

    Show answer & explanation

    Correct answer: B

    XSOAR Lists are designed to store static or dynamic data (like arrays of IPs, JSON objects, or text) that can be accessed and modified by playbooks and scripts globally.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the XSOAR-ENGINEER sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 210 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon