Chronicle SOAR Fundamentals Quiz Flashcards

1
Q

In case of multiple matches for an Alert, which Playbook priority determines precendence?

-None of the above
-Third
-Second
-First

A

First

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Where can you find an execution log of an Alert?

-Problem
-Chronicle SOAR blog
-Case
-Action

A

Case

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

By specifying a particular ____ field or general output of an action, you can create condition within a playbook.

-JSON
-Action
-Visualizations
-HTTP

A

JSON

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the mandatory checks required for installing a Use Case? (Select all that apply)

-Ensuring a test environment exists before downloading the use case
-Enabling simulations before downloading the integration
-Configuration of integretions
-Selection of integrations

A

-Configuration of integrations

-Selection of integrations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

_____ allow when a playbook is activated, the toggle

-Events
-Actions
-Playbooks
-Blocks

A

Blocks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A playbook can be attached to all Environments within the platform.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Can a user have restrictions to view certain environments within the platform?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What type of activities can be added by collaborators to the Command Center workstation?

-Fact
-Assessment
-Key Items
-Task
-Fact
-All of the above

A

All of the above

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

When selecting an active incident within Command Center, what filters can be applied under Workstation tab?

-Time
-Department
-Collaborator
-All of the above

A

All of the above

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Blocks can be used for

-Insight features
-Condition Features
Repeatable actions

A

Repeatable actions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

In Command Center, when creating a new status assessment, can you add a severity above 100?

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Multiple incidents can be transferred into the Command Center from a single of multiple Environments?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which of the following fields are displayed under “Entities Highlights” sections? (select all that apply).

-File Name
-Email Subject
-IP Address
-User Name

A

All of the above

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

When installing an integration (select all that apply)…

-Simply click the download button for your selected integration +++++++++++++
-Check if you require subscription for the integration to work optimally within Chronicle SOAR
-To download community edition you need permission from the creator
-Ensure the integration is compatible for your Chronicle SOAR version before downloading XXXXXXXXXXXXXXX

A

-Simply click the download button for your selected integration

incomplete

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is available under Configuration tab? (Select all that apply)

-Jobs
-Connectors
-Playbooks XXXXXXXXX
-Settings ++++

A

-Settings

this is correct but an incomplete answer, need to select more

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Analysts can communicate with any internal Chronicle SOAR user as part of the platform.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

When a playbook is activated, the toggle next to the playbook name appears green.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

A “Playbook” can only be attached to a specific Environment

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Red text within Chronicle SOAR Mapping represents

-Field mapped and no data in event
-Field mapped and Event has data
-Field not mapped

A

Field not mapped

20
Q

White text within Chronicle SOAR Mapping represents

-Field not mapped
-Field mapped and no data in event
-Field mapped and Event has data

A

Field mapped and no data in event

21
Q

A “Trigger” is the very first step in each playbook.

A

True

22
Q

What module should be used within Chronicle SOAR to monitor health checks and synchronization tasks?

-Jobs
-Connectors XXXXXXXX
-Insights XXXXXXXXX
-Integrations

A
23
Q

____ allows you to ingest raw source data into the platform?

-Ontology Mapping
-Connector
-Jobs
-IDE

A

Connnector

24
Q

Green text within Chronicle Mapping represents

-Field mapped and Event has data
-Field not mapped
-Field mapped and no data in event

A

Field mapped and Event has data

25
Q

A manual action within a playbook can be identified by

-“M” letter
-“MAN” letters XXXXXXX
-Hand symbol XXXXXX
-The purple color

A
26
Q

Which hierarchy is correct for Ontology?

A

Source -> Product -> Event

27
Q

It is possible to import or export a Dashboard

A

True

28
Q

Which widget includes a visual graph of the Case Entities?

-Alert Graph
-Entities Graph Widget
-Case Graph Widget
MITRE Graph Widget

A

Entities Graph Widget

29
Q

In playbook designer when you toggle the “Simulator” buttonwhat is the expected behavior?

A

The playbook can now be tested with simulated alerts

30
Q

You are limited to inviting internal users to the Command Center when collaborating on incidents.

A

False

31
Q

Playbook actions can be configured to be executed automatically or manually.

A

True

32
Q

A case tag can be added to high priorirt alerts only?

A

False

33
Q

Which Flow step required an analyst to maually answer a question?

A

MultiChoiceQuestion

34
Q

You can uninstall an integration that has a dependable playbook

A

True

35
Q

You need to configure an integrations before using it with the downloaded use cases

A

True

36
Q

Do you require multiple dashboards in order to configure data widgets that show results from multiple Environments

A

False

37
Q

Can PowerUp integration help you enhance your playbook capabilities?

A

True

38
Q

What tabs are available within Homepage?

-My Tasks
-Pending Actions
-Annoucements
-My Cases
-Workspace
-Your Cases
-Completed Actions

A

-Pending Actions
-Annoucements
-Workspace
-My Tasks

39
Q

Where can you check all Active System Modules?

-Permissions
-License Management
-Ontology XXXXXXX
-Integrations XXXXXXXX

A
40
Q

Can report templates be downloaded from the Chronicle SOAR Marketplace?

A

True

41
Q

When creating an playbook if you select “All Environments” button, what does such scope mean?

-The function will run all the time regardless of the playbook selection
-The function will run on all current Environments
-The function will run on all future Environments
-This function created within playbook will run on all current Environments as well as on all future environments

A

This function created within playbook will run on all current Environments as well as on all future environments

42
Q

All playbook triggers excepts “All” can be scope with the following parameters (Select all that apply)

-“=> More than or Equal to” XXXXXXXX
-“() Contains” +++++++
-“= Equal”
-“*_Starts With” +++++

A

”() Contains”
“*_Starts With”

incomplete

43
Q

What can you find within the Chronicle SOAR Marketplace (Select all that apply).

-Phishing Alert Tips
-Power Ups
-Analytics
-Integrations
-Vendors

A

Analytics
Power Ups
Integrations

44
Q

Conditions are built based on case data such as the following

-Cases
-Environments
-Entities XXXXXXXXX
-Events
-Alerts XXXXXXX
-All of the above XXXXXX

A
45
Q

Who typically has sufficient rights to turn off the “Simulator” mode? (Select all that apply).

-Admin
-None of these
-SOC Analyst
-SOC Manager

A

SOC Manager
Admin

46
Q

A playbook will only run if its priority is defined within the logic

A

False

47
Q

______ allows you to create repetitive steps within a workflow and they also allow you to put together a string of input and outputs.

A.) Actions
B.) Events
C.) Playbooks
D.) Blocks

A

Blocks