Chronicle SOAR Fundamentals Quiz Flashcards

1
Q

In case of multiple matches for an Alert, which Playbook priority determines precendence?

-None of the above
-Third
-Second
-First

A

First

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Where can you find an execution log of an Alert?

-Problem
-Chronicle SOAR blog
-Case
-Action

A

Case

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

By specifying a particular ____ field or general output of an action, you can create condition within a playbook.

-JSON
-Action
-Visualizations
-HTTP

A

JSON

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the mandatory checks required for installing a Use Case? (Select all that apply)

-Ensuring a test environment exists before downloading the use case
-Enabling simulations before downloading the integration
-Configuration of integretions
-Selection of integrations

A

-Configuration of integrations

-Selection of integrations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

_____ allow when a playbook is activated, the toggle

-Events
-Actions
-Playbooks
-Blocks

A

Blocks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A playbook can be attached to all Environments within the platform.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Can a user have restrictions to view certain environments within the platform?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What type of activities can be added by collaborators to the Command Center workstation?

-Fact
-Assessment
-Key Items
-Task
-Fact
-All of the above

A

All of the above

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

When selecting an active incident within Command Center, what filters can be applied under Workstation tab?

-Time
-Department
-Collaborator
-All of the above

A

All of the above

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Blocks can be used for

-Insight features
-Condition Features
Repeatable actions

A

Repeatable actions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

In Command Center, when creating a new status assessment, can you add a severity above 100?

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Multiple incidents can be transferred into the Command Center from a single of multiple Environments?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which of the following fields are displayed under “Entities Highlights” sections? (select all that apply).

-File Name
-Email Subject
-IP Address
-User Name

A

All of the above

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

When installing an integration (select all that apply)…

-Simply click the download button for your selected integration +++++++++++++
-Check if you require subscription for the integration to work optimally within Chronicle SOAR
-To download community edition you need permission from the creator
-Ensure the integration is compatible for your Chronicle SOAR version before downloading XXXXXXXXXXXXXXX

A

-Simply click the download button for your selected integration

incomplete

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is available under Configuration tab? (Select all that apply)

-Jobs
-Connectors
-Playbooks XXXXXXXXX
-Settings ++++

A

-Settings

this is correct but an incomplete answer, need to select more

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Analysts can communicate with any internal Chronicle SOAR user as part of the platform.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

When a playbook is activated, the toggle next to the playbook name appears green.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

A “Playbook” can only be attached to a specific Environment

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Red text within Chronicle SOAR Mapping represents

-Field mapped and no data in event
-Field mapped and Event has data
-Field not mapped

A

Field not mapped

20
Q

White text within Chronicle SOAR Mapping represents

-Field not mapped
-Field mapped and no data in event
-Field mapped and Event has data

A

Field mapped and no data in event

21
Q

A “Trigger” is the very first step in each playbook.

22
Q

What module should be used within Chronicle SOAR to monitor health checks and synchronization tasks?

-Jobs
-Connectors XXXXXXXX
-Insights XXXXXXXXX
-Integrations

23
Q

____ allows you to ingest raw source data into the platform?

-Ontology Mapping
-Connector
-Jobs
-IDE

A

Connnector

24
Q

Green text within Chronicle Mapping represents

-Field mapped and Event has data
-Field not mapped
-Field mapped and no data in event

A

Field mapped and Event has data

25
A manual action within a playbook can be identified by -"M" letter -"MAN" letters XXXXXXX -Hand symbol XXXXXX -The purple color
26
Which hierarchy is correct for Ontology?
Source -> Product -> Event
27
It is possible to import or export a Dashboard
True
28
Which widget includes a visual graph of the Case Entities? -Alert Graph -Entities Graph Widget -Case Graph Widget MITRE Graph Widget
Entities Graph Widget
29
In playbook designer when you toggle the "Simulator" buttonwhat is the expected behavior?
The playbook can now be tested with simulated alerts
30
You are limited to inviting internal users to the Command Center when collaborating on incidents.
False
31
Playbook actions can be configured to be executed automatically or manually.
True
32
A case tag can be added to high priorirt alerts only?
False
33
Which Flow step required an analyst to maually answer a question?
MultiChoiceQuestion
34
You can uninstall an integration that has a dependable playbook
True
35
You need to configure an integrations before using it with the downloaded use cases
True
36
Do you require multiple dashboards in order to configure data widgets that show results from multiple Environments
False
37
Can PowerUp integration help you enhance your playbook capabilities?
True
38
What tabs are available within Homepage? -My Tasks -Pending Actions -Annoucements -My Cases -Workspace -Your Cases -Completed Actions
-Pending Actions -Annoucements -Workspace -My Tasks
39
Where can you check all Active System Modules? -Permissions -License Management -Ontology XXXXXXX -Integrations XXXXXXXX
40
Can report templates be downloaded from the Chronicle SOAR Marketplace?
True
41
When creating an playbook if you select "All Environments" button, what does such scope mean? -The function will run all the time regardless of the playbook selection -The function will run on all current Environments -The function will run on all future Environments -This function created within playbook will run on all current Environments as well as on all future environments
This function created within playbook will run on all current Environments as well as on all future environments
42
All playbook triggers excepts "All" can be scope with the following parameters (Select all that apply) -"=> More than or Equal to" XXXXXXXX -"() Contains" +++++++ -"= Equal" -"*_Starts With" +++++
"() Contains" "*_Starts With" incomplete
43
What can you find within the Chronicle SOAR Marketplace (Select all that apply). -Phishing Alert Tips -Power Ups -Analytics -Integrations -Vendors
Analytics Power Ups Integrations
44
Conditions are built based on case data such as the following -Cases -Environments -Entities XXXXXXXXX -Events -Alerts XXXXXXX -All of the above XXXXXX
45
Who typically has sufficient rights to turn off the "Simulator" mode? (Select all that apply). -Admin -None of these -SOC Analyst -SOC Manager
SOC Manager Admin
46
A playbook will only run if its priority is defined within the logic
False
47
______ allows you to create repetitive steps within a workflow and they also allow you to put together a string of input and outputs. A.) Actions B.) Events C.) Playbooks D.) Blocks
Blocks