Palo-alto-networks

PCSAE practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 97-question bank.

Provider
Palo-alto-networks
Question bank
97
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for PCSAE, a certification listed under Palo-alto-networks. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Palo-alto-networks. The certification credential is issued by Palo-alto-networks, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Which two advanced attributes can be applied to incident fields when editing? (Choose two.)

    Choose all answers that apply.

    • Set a field trigger script
    • Associate to an incident type
    • Change field type
    • Change field name
  2. Question 2 · 1

    Which two causes may be occurring if an integration test is working, but the integration is not fetching incidents? (Choose two.)

    Choose all answers that apply.

    • The 'Fetches Incidents' option may not have been enabled
    • There are no new events from the external service
    • The first fetch should be manually triggered to start the fetching process
    • It can take up to 1-hour before incidents are initially fetched
  3. Question 3 · 1

    Which of the following is a feature of XSOAR automations?

    Choose one answer.

    • can run on multiple docker containers
    • can be set to run on a scheduled basis in the automation settings
    • can be password protected
    • can be written in C++
  4. Question 4 · 1

    When is the post-processing script executed in XSOAR?

    Choose one answer.

    • Just after the incident is created
    • Just after the pre-processing is executed
    • Just after the playbook is executed
    • Just after the Close Incident button is clicked
  5. Question 5 · 1

    Which option is available in XSOAR to create the body of a Threat Intel Report?

    Choose one answer.

    • Markdown
    • Grid Fields
    • DOC format
    • Javascript
  6. Question 6 · 1

    Given the following context data, what would be the expected output of the expression?

    Choose one answer.

    Question illustration 1
    • 1E56733826E5035233A097FCEA2046AF96EC616C
    • E6EF5142E2553C1E442A0FFAC07636EAC61E6EDD
    • 8D193FA162A305E4859BA8C45F5121F7265E3ABB
    • e6ef5142e2553c1e442a0ffac07636eac61e6edd
  7. Question 7 · 1

    Where are incident layouts customized?

    Choose one answer.

    • Settings > Object Setup > Incidents > Layouts
    • Settings > Integrations > Instance configuration
    • Settings > Object Setup > Indicators > Layouts
    • Settings > Advanced > Incident Layouts
  8. Question 8 · 1

    Which content type cannot be managed using remote repositories?

    Choose one answer.

    • Lists
    • Jobs
    • Pre-processing rules
    • Exclusion List
  9. Question 9 · 1

    Which two capabilities do Automation script settings include? (Choose two.)

    Choose all answers that apply.

    • Define 'parameters'
    • Correlate to incident types
    • Define 'outputs'
    • Set password protection
  10. Question 10 · 1

    After executing the DeleteContext automation with all=yes argument, how would the context data of an incident present?

    Choose one answer.

    • All the data, including the incident key will be deleted, and the context data will be completely empty.
    • No difference, the automation cannot be executed manually.
    • All context data, including custom incident fields will be deleted, system incident fields will remain.
    • All context data, except the incident key will be deleted.
  11. Question 11 · 1

    An XSOAR engineer has been tasked with exporting all indicators from the production environment in the last 90 days. The final report needs to be in CSV format containing all indicator fields. How can this task be achieved?

    Choose one answer.

    • Run the command !GetIndicatorsByQuery in CLI with its default arguments and export all indicators in the last 90 days.
    • SSH into the server and copy the indicator's database.
    • In the Threat Intel page, add query firstSeen:>="90 days ago", select All columns in Table View, and click Export to export as a CSV.
    • Run the command !findIndicators in CLI with the query firstSeen:>="90 days ago" and export to CSV.
  12. Question 12 · 1

    An administrator has noticed that an incident fetch has failed, causing several internal workflows to be backed up. The administrator would like to receive notifications the next time the incident fetch fails. How can they achieve this?

    Choose one answer.

    • Create a custom playbook that sends an email each time the fetch fails.
    • Create a new integration that monitors the incident fetch and sends an email if the fetch fails.
    • Schedule a job that runs and monitors incidents in XSOAR that will send an email if there are no new incidents.
    • Add a server config to notify when incident fetch fails.
  13. Question 13 · 1

    An administrator wants to run an automation in the War Room to set the incident field "Description" to "Confirmed Phishing". Which command should they enter in the War Room CLI?

    Choose one answer.

    • !incidentSet description="Confirmed Phishing"
    • /incidentSet description=Confirmed Phishing
    • !setIncident description="Confirmed Phishing"
    • /setIncident description=Confirmed Phishing
  14. Question 14 · 1

    Select the correct incident life cycle on XSOAR.

    Choose one answer.

    • Planning > Incident Ingestion > Incident Creation > Mapping and Classification > Pre-processing > Playbook runs > Post-processing
    • Planning > Incident Ingestion > Pre-processing > Incident Creation > Mapping and Classification > Playbook runs > Post-processing
    • Planning > Incident Ingestion > Pre-processing > Mapping and Classification > Incident Creation > Playbook runs > Post-processing
    • Planning > Incident Ingestion > Mapping and Classification > Pre-processing > Incident Creation > Playbook runs > Post-processing
  15. Question 15 · 1

    At what stage during the incident lifecycle is an incident type assigned?

    Choose one answer.

    • Pre-processing
    • Incident creation
    • Classification
    • Playbook execution

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free