What is the default configuration for indicator auto-extraction when incidents are created?
An analyst wants to run a script to remove usernames from an incident before the incident becomes active in XSOAR. How can this be achieved?
If a known malicious domain is no longer associated with a specific IP address, which action will make the association inactive?.
Based on the images below,

what will be the result of the Filters and Transformers?.
An engineer is developing a playbook that will be run multiple times for testing purposes. What is the recommended first task to be used in the playbook?
A SOC analyst needs to retrieve the list of all open phishing incidents in the last 30 days. What is the correct query to use?
Where do you navigate to monitor and improve the system performance and resilience for hosts in a multitenant environment?
Threat Intel search queries can be shared with which of the following? (Select 1)
Reliability scores in XSOAR range from A through F. What do A and F stand for?
Arrange these steps in the order that they occur during an incident fetch.

Which tag must be applied to an Automation Script in order for it to be available when configuring an Indicator Type?
What is the most effective way to correlate multiple raw events coming from a SIEM and link them together?
In Cortex XSOAR multi tenant setup, when content from a development server is pushed to the remote repository, where in the production server can the updates be found?
Which task type would be used to verify/check that an integration was enabled?
In which two ways can data be transferred between playbooks and sub-playbooks? (Choose two.)
An engineer wants to customize the regex for the default IP indicator type. How can this change be implemented?
Which command adds or updates a description to an incident that can be used within widgets?
Which command adds or updates a description to an incident that can be used within widgets?.
Newly created subplaybooks do not have any inputs, or outputs. What is necessary to make them functional? (Choose two.)
A SOC team must send a notification email to specific teams based on the severity of an incident.
Which feature will accomplish this task each time the severity escalates?.
Which option is available in XSOAR to create the body of a Threat Intel Report?
What are inputs and outputs in reference to a Playbook Development Lifecycle? (Choose three.)
Can an automation script execute an integration command and an integration command execute an automation script?
When creating an automation in XSOAR, what is the best way to create a log message?
An engineer would like to add a custom field to the New Job form for a job triggered from a threat intel feed. How would the engineer implement this?
A Cortex XSOAR Administrator is tasked with building a button for an analyst in order for the analyst to be assigned to the incident as an owner. What is the process?
What is the correct way to install different engines on the same Ubuntu machine for a Dev/Prod setup?.
An administrator has noticed that an integration has failed to fetch incidents. Where would they go to download logs to troubleshoot the error?
Which two features does XSOAR offer to help recover from a server failure? (Choose two.)
How would context data be filtered to receive only malicious indicator values with DBotScore?
What is an outcome of using sections within a tab when customizing an incident layout?.
Which of the following is a basic setting that can be configured in an automation?
When mapping incoming data to incident fields, which statement is correct?
Which two options will troubleshoot an integration’s fetch incidents command? (Choose two.)
Which three options can be defined in the layout settings? (Choose three.)
Which two reasons would lead an engineer to create a custom widget? (Choose two.)
Which of the following is a prerequisite to editing out-of-the-box (OOTB) content?
When using the playbook debugger, what may be the cause of a starred incident missing from the Test Data selections?.
An engineer defined a dashboard which allows important metrics to be displayed. The engineer would like to make this dashboard the default dashboard.
How can it be accomplished?
The default expiration method for non-feed indicators is either to never expire or to expire after a specific period of time. How frequently does XSOAR check tor newly expired indicators?
Which three authentication methods are supported when logging into XSOAR? (Choose three.)
Which of the following are valid methods to contribute custom content? (Choose three.)
In a Dev/Prod deployment model, what is available only in the development tenant?.
In order to automatically run a playbook on the indicators fetched by an integration, what would an XSOAR Administrator setup?
For troubleshooting, after a log bundle is created, where do the logs appear on the XCSOAR server?
You need to retrieve a list of all malicious hashes over the last 30 days. What is the correct query to use?