exam questions

Exam PCSAE All Questions

View all questions & answers for the PCSAE exam

Exam PCSAE topic 1 question 117 discussion

Actual exam question from Palo Alto Networks's PCSAE
Question #: 117
Topic #: 1
[All PCSAE Questions]

Select the correct incident life cycle on XSOAR.

  • A. Planning > Incident Ingestion > Incident Creation > Mapping and Classification > Pre-processing > Playbook runs > Post-processing
  • B. Planning > Incident Ingestion > Pre-processing > Incident Creation > Mapping and Classification > Playbook runs > Post-processing
  • C. Planning > Incident Ingestion > Pre-processing > Mapping and Classification > Incident Creation > Playbook runs > Post-processing
  • D. Planning > Incident Ingestion > Mapping and Classification > Pre-processing > Incident Creation > Playbook runs > Post-processing
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Sarppp
Highly Voted 1 year, 8 months ago
D https://xsoar.pan.dev/docs/incidents/incident-xsoar-incident-lifecycle
upvoted 5 times
...
Jai_ke
Most Recent 8 months, 1 week ago
Selected Answer: D
Planning: Defining how incidents will be managed. Incident Ingestion: Gathering data from various sources. Mapping and Classification: Mapping incoming data to incident fields and classifying the incident type. Pre-processing: Applying pre-processing rules to determine how the incident should be handled. Incident Creation: Officially creating the incident in the system. Playbook runs: Executing the automated response playbooks. Post-processing: Final steps taken before closing the incident.
upvoted 1 times
...
piipo
1 year, 1 month ago
Selected Answer: D
D is correct
upvoted 1 times
...
franko_72
1 year, 9 months ago
Sorry, it's A - Here is why: Stage 1 - Event Ingestion Stage Two: Incident Object Creation Cortex XSOAR uses the event data fetched by an integration to create an incident object and populates it with raw event data.
upvoted 1 times
...
franko_72
1 year, 9 months ago
I think it is D - The pre-processing rule defines what to do if incident is of type X, therefore there has to be an incident for this to occur. Planning > Incident Ingestion > Mapping and Classification > Pre-processing > Incident Creation > Playbook runs > Post-processing
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago