exam questions

Exam PCSAE All Questions

View all questions & answers for the PCSAE exam

Exam PCSAE topic 1 question 137 discussion

Actual exam question from Palo Alto Networks's PCSAE
Question #: 137
Topic #: 1
[All PCSAE Questions]

A SOC analyst needs to retrieve the list of all open phishing incidents in the last 30 days. What is the correct query to use?

  • A. -status:closed -category:job type:Phishing created:>="30 days ago"
  • B. status:closed -category:job & type:Phishing created:>="30 days ago"
  • C. -status:closed -category:job & type:Phishing created:<="30 days ago"
  • D. -status:closed -category:job type:Phishing created:="30 days ago"
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Jai_ke
8 months, 3 weeks ago
Selected Answer: C
>= means greater than and <= means lesser than or equal to so the answer should be C.
upvoted 1 times
Jai_ke
8 months, 1 week ago
I got confused. The they are correct, A is the answer. >= "30 days ago": This query will include all incidents created from 30 days ago up to the current time. <= "30 days ago": This would include incidents created on or before 30 days ago, excluding any incidents created after that point. This does not include incidents within the last 30 days.
upvoted 1 times
...
...
gabriel.alarcon0730
8 months, 4 weeks ago
Selected Answer: A
A is correct
upvoted 1 times
...
piipo
1 year, 1 month ago
Selected Answer: A
A is correct
upvoted 1 times
...
franko_72
1 year, 9 months ago
Answer is A for my XSOAR
upvoted 4 times
...
franko_72
1 year, 9 months ago
Not sure if any of these answers are correct. On my XSOAR this query works: -status:Closed -category:job and type:Phishing created:>="30 days ago" Notice the 'and' and not '&' and the >= not <= operators So, the -status closed means NOT closed as the - means the opposite. The -category job means anything but jobs as again the - means 'not' The greater than or equal to is a weird one, I just created a test phishing incident so I would of thought all Phishing incidents greater than or equal to 30 days ago.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago