When a sub-playbook loops, which task tab will allow an analyst to determine what data the sub- playbook used in each iteration of the loop?
A. Inputs
B. Input Results
C. Results
D. Outputs
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
In addition to defining the Rule Name and Severity Level, which step or set of steps accurately reflects how an analyst should configure an indicator prevention rule before reviewing and saving it?
A. Select profiles for prevention.
Filter and select one or more file, IP address, and domain indicators.
B. Filter and select file, IP address, and domain indicators.
C. Filter and select indicators of any type.
D. Select profiles for prevention.
Filter and select one or more SHA256 and MD5 indicators.
正解:A
質問 3:
Two security analysts are collaborating on complex but similar incidents. The first analyst merges the two incidents into one for easier management. The other analyst immediately discovers that the custom incident field values relevant to the investigation are missing.
How can the team retrieve the missing details?
A. Unmerge the incidents to capture the missing details
B. Check the timeline view of the incident.
C. Check the War Room of the destination incident.
D. Examine the incident context of the source incident.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
Which type of alert in Cortex XSIAM is primarily based on endpoint telemetry and behavior?
A. XDR Agent
B. BIOC
C. Correlation
D. IOC
正解:B
質問 5:
Which attributes can be used as featured fields?
A. Device-ID, URL, port, and indicator
B. CIDR range, file hash, tags, and log source
C. Hostnames, user names, IP addresses, and Active Directory
D. Endpoint-ID, alert source, critical asset, and threat name
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
How would Incident Context be referenced in an alert War Room task or alert playbook task?
A. ${parentIncidentFields}
B. ${getParentIncidentContext}
C. ${getparentIncidentFields}
D. ${parentIncidentContext}
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 7:
What information is provided in the timeline view of Cortex XSIAM?
A. Sequence of events, alerts, rules, and other actions involved over the lifespan of an incident
B. Detailed overview of behavior or activity that triggered an Analytics Alert, Analytics BIOC alert, or correlation rule
C. Tab within an incident where analysts can collaborate and initiate further actions and automations
D. Graphic representation of an event Causality Instance (CI) with additional capabilities to enable further analysis
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
719 お客様のコメント





Sakaki -
XSIAM-Analyst合格できました!試験だけをとってみても試験の設問がほぼ同じ問題がでたりと大助かりでした。
ありがとうございました。