Chronicle SOAR Fundamentals Quiz Flashcards
In case of multiple matches for an Alert, which Playbook priority determines precendence?
-None of the above
-Third
-Second
-First
First
Where can you find an execution log of an Alert?
-Problem
-Chronicle SOAR blog
-Case
-Action
Case
By specifying a particular ____ field or general output of an action, you can create condition within a playbook.
-JSON
-Action
-Visualizations
-HTTP
JSON
What are the mandatory checks required for installing a Use Case? (Select all that apply)
-Ensuring a test environment exists before downloading the use case
-Enabling simulations before downloading the integration
-Configuration of integretions
-Selection of integrations
-Configuration of integrations
-Selection of integrations
_____ allow when a playbook is activated, the toggle
-Events
-Actions
-Playbooks
-Blocks
Blocks
A playbook can be attached to all Environments within the platform.
True
Can a user have restrictions to view certain environments within the platform?
True
What type of activities can be added by collaborators to the Command Center workstation?
-Fact
-Assessment
-Key Items
-Task
-Fact
-All of the above
All of the above
When selecting an active incident within Command Center, what filters can be applied under Workstation tab?
-Time
-Department
-Collaborator
-All of the above
All of the above
Blocks can be used for
-Insight features
-Condition Features
Repeatable actions
Repeatable actions
In Command Center, when creating a new status assessment, can you add a severity above 100?
False
Multiple incidents can be transferred into the Command Center from a single of multiple Environments?
True
Which of the following fields are displayed under “Entities Highlights” sections? (select all that apply).
-File Name
-Email Subject
-IP Address
-User Name
All of the above
When installing an integration (select all that apply)…
-Simply click the download button for your selected integration +++++++++++++
-Check if you require subscription for the integration to work optimally within Chronicle SOAR
-To download community edition you need permission from the creator
-Ensure the integration is compatible for your Chronicle SOAR version before downloading XXXXXXXXXXXXXXX
-Simply click the download button for your selected integration
incomplete
What is available under Configuration tab? (Select all that apply)
-Jobs
-Connectors
-Playbooks XXXXXXXXX
-Settings ++++
-Settings
this is correct but an incomplete answer, need to select more
Analysts can communicate with any internal Chronicle SOAR user as part of the platform.
True
When a playbook is activated, the toggle next to the playbook name appears green.
True
A “Playbook” can only be attached to a specific Environment
False
Red text within Chronicle SOAR Mapping represents
-Field mapped and no data in event
-Field mapped and Event has data
-Field not mapped
Field not mapped
White text within Chronicle SOAR Mapping represents
-Field not mapped
-Field mapped and no data in event
-Field mapped and Event has data
Field mapped and no data in event
A “Trigger” is the very first step in each playbook.
True
What module should be used within Chronicle SOAR to monitor health checks and synchronization tasks?
-Jobs
-Connectors XXXXXXXX
-Insights XXXXXXXXX
-Integrations
____ allows you to ingest raw source data into the platform?
-Ontology Mapping
-Connector
-Jobs
-IDE
Connnector
Green text within Chronicle Mapping represents
-Field mapped and Event has data
-Field not mapped
-Field mapped and no data in event
Field mapped and Event has data
A manual action within a playbook can be identified by
-“M” letter
-“MAN” letters XXXXXXX
-Hand symbol XXXXXX
-The purple color
Which hierarchy is correct for Ontology?
Source -> Product -> Event
It is possible to import or export a Dashboard
True
Which widget includes a visual graph of the Case Entities?
-Alert Graph
-Entities Graph Widget
-Case Graph Widget
MITRE Graph Widget
Entities Graph Widget
In playbook designer when you toggle the “Simulator” buttonwhat is the expected behavior?
The playbook can now be tested with simulated alerts
You are limited to inviting internal users to the Command Center when collaborating on incidents.
False
Playbook actions can be configured to be executed automatically or manually.
True
A case tag can be added to high priorirt alerts only?
False
Which Flow step required an analyst to maually answer a question?
MultiChoiceQuestion
You can uninstall an integration that has a dependable playbook
True
You need to configure an integrations before using it with the downloaded use cases
True
Do you require multiple dashboards in order to configure data widgets that show results from multiple Environments
False
Can PowerUp integration help you enhance your playbook capabilities?
True
What tabs are available within Homepage?
-My Tasks
-Pending Actions
-Annoucements
-My Cases
-Workspace
-Your Cases
-Completed Actions
-Pending Actions
-Annoucements
-Workspace
-My Tasks
Where can you check all Active System Modules?
-Permissions
-License Management
-Ontology XXXXXXX
-Integrations XXXXXXXX
Can report templates be downloaded from the Chronicle SOAR Marketplace?
True
When creating an playbook if you select “All Environments” button, what does such scope mean?
-The function will run all the time regardless of the playbook selection
-The function will run on all current Environments
-The function will run on all future Environments
-This function created within playbook will run on all current Environments as well as on all future environments
This function created within playbook will run on all current Environments as well as on all future environments
All playbook triggers excepts “All” can be scope with the following parameters (Select all that apply)
-“=> More than or Equal to” XXXXXXXX
-“() Contains” +++++++
-“= Equal”
-“*_Starts With” +++++
”() Contains”
“*_Starts With”
incomplete
What can you find within the Chronicle SOAR Marketplace (Select all that apply).
-Phishing Alert Tips
-Power Ups
-Analytics
-Integrations
-Vendors
Analytics
Power Ups
Integrations
Conditions are built based on case data such as the following
-Cases
-Environments
-Entities XXXXXXXXX
-Events
-Alerts XXXXXXX
-All of the above XXXXXX
Who typically has sufficient rights to turn off the “Simulator” mode? (Select all that apply).
-Admin
-None of these
-SOC Analyst
-SOC Manager
SOC Manager
Admin
A playbook will only run if its priority is defined within the logic
False
______ allows you to create repetitive steps within a workflow and they also allow you to put together a string of input and outputs.
A.) Actions
B.) Events
C.) Playbooks
D.) Blocks
Blocks