XSOAR-ENGINEER Sample Questions

XSOAR-ENGINEER Sample Questions & Answers

Built around playbook task configuration tied closely with context data management, the top-weighted skill, plus threat intelligence configuration, War Room activity, engine deployment and authentication, and the incident and indicator lifecycle.

Launch the full XSOAR-ENGINEER simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Use Case Planning and Development · Classifier and mapper configuration

    A security engineer is configuring a new classifier for email-based incidents. The requirement is to classify emails with the subject 'Phishing Alert' as 'Phishing' incidents, and emails with 'Malware Detected' as 'Malware' incidents. All other emails should be classified as 'General'. Which configuration step is essential to achieve this?

    Show answer & explanation

    Correct answer: B

    The classifier evaluates rules. If a rule matches 'Phishing Alert', it sets the type. If no rules match, the system uses the Default Incident Type configured in the integration or classifier settings.

  2. Question 2Intermediate

    Use Case Planning and Development · Classifier and mapper configuration

    You are mapping a JSON alert from a SIEM to XSOAR fields. The JSON structure contains a nested field: {"alert": {"details": {"source_ip": "192.168.1.1"}}}. Which syntax correctly extracts the IP address in the Mapper configuration?

    Show answer & explanation

    Correct answer: A

    In XSOAR Mappers, dot notation is used to traverse nested JSON objects to extract specific values.

  3. Question 3Intermediate

    Use Case Planning and Development · Field and layout configuration

    A layout for the 'Phishing' incident type must show a specific tab called 'Forensics' ONLY if the incident severity is 'High' or 'Critical'. How should this be configured?

    Show answer & explanation

    Correct answer: B

    Tabs and sections in layouts can have display conditions configured directly in the Layout Editor. These conditions can check field values like 'severity' to determine visibility.

  4. Question 4Beginner

    Use Case Planning and Development · Incident type configuration

    You are creating a custom Incident Type 'Malware Investigation'. You want to ensure that whenever an incident of this type is created, a specific playbook 'Malware Response v2' is automatically assigned and executed. Where do you configure this association?

    Show answer & explanation

    Correct answer: B

    The association between an Incident Type and its default playbook is defined in the Incident Type configuration page.

  5. Question 5Beginner

    Use Case Planning and Development · List management

    A developer needs to store a list of malicious IP addresses that are updated daily by an external threat feed. This list will be used by multiple playbooks to block traffic. Which Cortex XSOAR feature is best suited for storing and managing this data?

    Show answer & explanation

    Correct answer: C

    XSOAR Lists are designed to store static or dynamic data (like arrays of IPs, JSON objects, or text) that can be accessed and modified by playbooks and scripts globally.

  6. Question 6Advanced

    Use Case Planning and Development · Incident creation methods

    Case Study Scenario:

    GlobalCorp is implementing XSOAR to handle high volumes of firewall alerts. They want to deduplicate incidents to avoid alert fatigue.

    The requirement is: If a new alert arrives with the same 'Source IP' and 'Destination Port' as an existing open incident, it should update the existing incident rather than creating a new one.

    Which configuration combination achieves this?

    Show answer & explanation

    Correct answer: A

    The standard way to handle deduplication in XSOAR is via Preprocessing Rules. You can set the rule to identify existing incidents based on specific fields (Source IP, Dest Port) and then choose an action like 'Link and Close' (create new but close it immediately linked to old) or update the existing one via script logic if needed. However, the native 'Deduplicate' script often used in pre-processing handles finding and linking.

  7. Question 7Intermediate

    Use Case Planning and Development · Incident type configuration

    Which feature allows an administrator to define specific timeframes (e.g., 'Business Hours') and associate them with SLA timers, ensuring that SLA clocks pause during nights and weekends?

    Show answer & explanation

    Correct answer: A

    While 'Calendars' are part of the system, the specific configuration for SLAs typically involves defining these timeframes in the SLA configuration, often referred to as SLA calendars or associated with Shift Management, but functionally XSOAR uses System Calendars to define working hours for SLAs.

  8. Question 8Intermediate

    Use Case Planning and Development · Preprocessing and postprocessing

    You are creating a Preprocessing Rule to ignore alerts from a specific scanner IP 10.10.5.5. Which operator should you use in the rule query to ensure incidents are NOT created for this IP?

    Show answer & explanation

    Correct answer: A

    In a Preprocessing Rule configured to 'Drop' or 'Ignore', you define the filter for the alerts you want to MATCH the rule. So if you want to drop alerts from 10.10.5.5, the query must match that IP.

  9. Question 9Advanced

    Playbook Development · Context data management

    In a playbook, you have a list of file hashes in the context key File.Hash. You need to filter this list to only include hashes where the Malicious.Vendor field is 'VirusTotal'. Which DT (Demisto Transform) expression achieves this?

    Show answer & explanation

    Correct answer: D

    The DT syntax Key(val.FilterCondition) allows filtering arrays. Here, we check if Malicious exists and if its Vendor property equals 'VirusTotal'.

  10. Question 10Advanced

    Playbook Development · Sub-playbook configuration

    You are building a playbook that iterates over a list of users to reset their passwords. If the password reset fails for one user, the playbook must log the error and continue to the next user without stopping. How should the sub-playbook loop be configured?

    Show answer & explanation

    Correct answer: B

    The 'Continue on error' setting on the specific command task within the sub-playbook (or the sub-playbook task itself depending on granularity) ensures that an exception raised by one iteration does not halt the entire playbook execution.

Ready for the real thing?

The full XSOAR-ENGINEER simulator has every exam-style question, timed mode, and instant scoring.