PCSAE Sample Questions

PCSAE Sample Questions & Answers

Draws on context data management alongside playbook task configuration, the single biggest weight, plus marketplace content customization, scripts versus commands for automation, incident types, fields and layouts, investigation dashboards, and threat intelligence.

Launch the full PCSAE simulator →

Showing 10 of 20 free samples.

  1. Question 1IntermediateSelect 2

    Incident Objects · Configure an incident layout

    An XSOAR administrator has configured a new incident type for 'Insider Threat' and is now designing the corresponding layout. A key requirement is to display an employee's detailed HR information (manager, department, start date) dynamically when an analyst is viewing the incident. This data resides in an external HR system accessible via an integration. Which combination of XSOAR features should be used to implement this? (Select TWO).

    Show answer & explanation

    Correct answers: A, D

  2. Question 2Beginner

    Playbook Development · Differentiate among playbook task types

    A financial services company uses Cortex XSOAR for incident response. Due to strict compliance requirements, they need to implement a 'four-eyes' principle for any destructive action, such as blocking a C2 server's IP address. The action must be initiated by a Tier 1 analyst and then explicitly approved by a Tier 2 analyst before execution. Which playbook task type is specifically designed to handle this human-in-the-loop approval workflow?

    Show answer & explanation

    Correct answer: B

    The Data Collection task is the correct choice for implementing approval workflows. It can be configured to present a question with specific options (e.g., 'Approve', 'Deny') to a user or role (Tier 2 Analyst). The playbook execution pauses at this task until the required input is provided. The subsequent tasks can then use the response from the data collection task in a conditional path to either execute the destructive action or skip it.

  3. Question 3Beginner

    Automations, Integrations, and Related Concepts · Differentiate between automations, commands, and scripts

    True or False: When an integration instance is configured in Cortex XSOAR, its commands can ONLY be executed from within a playbook task and not directly from the War Room CLI.

    Show answer & explanation

    Correct answer: B

    This statement is false. A fundamental feature of XSOAR is the ability to run integration commands directly from the War Room command-line interface (CLI). This is crucial for interactive investigation, testing integration connectivity, and performing ad-hoc actions without needing a pre-built playbook. Commands are accessible via the ! prefix, for example, !ip ip=8.8.8.8.

  4. Question 4Intermediate

    Playbook Development · Apply filters and transformers to manipulate data

    An engineer needs to transform a string of comma-separated IP addresses, stored in the context at Email.AttackerIPs, into a JSON array for use as input to a sub-playbook. The input string looks like: "1.1.1.1,2.2.2.2,3.3.3.3". Which filter or transformer should be applied to achieve this?

    Show answer & explanation

    Correct answer: C

    The 'split' transformer is specifically designed for this task. It takes a string and a delimiter as arguments and returns an array of substrings. Applying a split transformer with a comma delimiter to the input string "1.1.1.1,2.2.2.2,3.3.3.3" will correctly produce the required JSON array ["1.1.1.1", "2.2.2.2", "3.3.3.3"] that can be used for looping in a sub-playbook.

  5. Question 5Intermediate

    Content Management and Solution Architecture · Define the capabilities of RBAC

    A new SOC analyst reports that they cannot see the 'Malware Analysis' tab on incidents of type 'Malware', but senior analysts can. The XSOAR administrator has confirmed the analyst has a role that grants access to the 'Malware' incident type. What is the most likely cause of this issue?

    Show answer & explanation

    Correct answer: B

    In Cortex XSOAR, the visibility of specific tabs within an incident layout can be controlled by role. When configuring a layout, each tab (section) has a 'Roles' setting that dictates which user roles can view it. The most probable cause is that the 'Malware Analysis' tab has been explicitly configured to be visible only to the 'Senior Analyst' role (or a similar high-privilege role) and not the 'SOC Analyst' role, even if both roles have access to the incident type itself.

  6. Question 6Intermediate

    Incident Objects · Configure classifiers and mappers

    When configuring an integration instance, an engineer enables the 'Fetches incidents' parameter. What additional objects must be configured for XSOAR to correctly process and categorize the incoming data from this integration into new incidents?

    Show answer & explanation

    Correct answer: C

    The incident ingestion process for fetching integrations relies on two key components: a Classifier and a Mapper. The Classifier inspects the raw incoming data (the 'fetch blob') to determine which Incident Type it should be assigned. Once classified, the Mapper takes the data from the blob and maps its key-value pairs to the specific fields within the designated XSOAR Incident Type. Without both, the fetched data cannot be correctly turned into a structured incident.

  7. Question 7Intermediate

    Content Management and Solution Architecture · Identify options available for performance tuning

    A Cortex XSOAR system is experiencing performance degradation. Upon investigation using the 'System Diagnostics' page, the administrator notices that the 'COMMANDS_EXECUTED' queue is consistently high. This indicates a bottleneck in command execution. Which of the following is a valid performance tuning option specifically designed to alleviate the load from automations that produce large, non-essential outputs?

    Show answer & explanation

    Correct answer: B

    Quiet Mode is a performance tuning feature that prevents command results, inputs, and outputs from being written to the War Room and context data. This is particularly useful for high-frequency, low-importance commands (like polling tasks) or those that produce verbose outputs that are not needed for subsequent playbook logic. By enabling Quiet Mode, you reduce the load on the database and Elasticsearch, which can help clear the command execution queue and improve overall system performance.

  8. Question 8Beginner

    UI Workflow, Dashboards, and Reports · Summarize what information can be created, edited, or shared within dashboards and reports

    An engineer creates a custom dashboard to track phishing incident metrics. They want to share this dashboard with the entire SOC team, but not with other departments who also have access to XSOAR. How can the engineer ensure the dashboard is visible only to the intended audience?

    Show answer & explanation

    Correct answer: C

    Cortex XSOAR dashboards have built-in, role-based access controls. When creating or editing a dashboard, the 'Permissions' setting allows the creator to specify which roles can view or edit it. To meet the requirement, the engineer should set the permissions to the role(s) assigned to the SOC team (e.g., 'SOC Analyst', 'SOC Manager') and no others. This ensures only users with those roles will see and be able to access the dashboard.

  9. Question 9Intermediate

    Content Management and Solution Architecture · Manage local changes in a remote repository (dev-prod) configuration

    In a dev-prod XSOAR environment, a developer has made changes to a playbook in the development instance. They now need to migrate this single, updated playbook to the production instance without overwriting other content. The instances are connected via a remote Git repository. What is the correct sequence of actions?

    Show answer & explanation

    Correct answer: B

    The 'Local Changes' page is the designated interface for managing content synchronization in a dev-prod setup. The correct process is to go to this page in the development instance, find the specific playbook that was modified, select it, and use the 'Push' action. This commits the change for that specific content item to the remote Git repository. Subsequently, an administrator on the production instance can go to the same page and use the 'Pull' action to retrieve and apply the update from the repository.

  10. Question 10BeginnerSelect 3

    Playbook Development · Differentiate among playbook task types

    Which of the following are valid playbook task types in Cortex XSOAR? (Select THREE).

    Show answer & explanation

    Correct answers: A, C, D

Ready for the real thing?

The full PCSAE simulator has every exam-style question, timed mode, and instant scoring.

Go to the PCSAE simulator →