Do you know that you can access more real exam questions via Premium Access? ()
An administrator has noticed that an incident fetch has failed, causing several internal workflows to be backed up. The administrator would like to receive notifications the next time the incident fetch fails.
How can they achieve this?
Answer : B
An analyst runs the following command in a playbook task:
!ip ip=1.1.1.1
Which extraction mode needs to be enabled on the Advanced tab of the playbook task to synchronously extract indicators from the results of this command?
Answer : D
What can you use to assign a layout, field, and playbook to an incoming incident?
Answer : B
For troubleshooting, after a log bundle is created, where do the logs appear on the XCSOAR server?
Answer : D
Which two functions in XSOAR are incident types used for? (Choose two.)
Answer : B, C