Exam PCSAE All QuestionsBrowse all questions from this exam
Question 25

DRAG DROP -

Arrange these steps in the order that they occur during an incident fetch.

Select and Place:

    Correct Answer:

Discussion
pawkers

I do not think so. It should be like that: Integration performs Classification is applied Mapping is applied Incident is created (before incident creation it should be also pre-process rule step)

appopay

the incident object is created right after the integration performs, after the mapping and pre-process, the incident is made to be available. but in fact it is created right after the integration performs. source beacon: Palo Alto Networks Certified Security Automation Engineer (PCSAE) -> Cortex XSOAR: SOAR Engineer Training -> Incident Classification and Mapping

Sarppp

Wrong, when you just search 'lifecycle of an incident in xsoar' you will see that in order: 1)Event Data Ingestion 2)Incident-Object Creation 3)Classification 4)Mapping 5)Pre-Process 6)Incident Process 7)Incident Management

thorodp

For future reference. This is wrong. The correct order is: Integration performs Incident is created Classification is applied Mapping is applied

PenguPC

I agree https://xsoar.pan.dev/docs/integrations/fetching-incidents

franko_72

Stage One: Event-Data Ingestion The incident lifecycle begins when an integration fetches an event. You can configure integrations in Cortex XSOAR to fetch event data from various sources, such as a SIEM, EDR, a firewall, and other security systems and services. Stage Two: Incident Object Creation Cortex XSOAR uses the event data fetched by an integration to create an incident object and populates it with raw event data. Stage Three: Classification Cortex XSOAR identifies the type of incident based on the classifier object selected in the integration configuration settings. If you have not selected any classifier, then the integration uses the default classifier of the integration. Cortex XSOAR will identify an incident as Unclassified if no default classifier exists or if the type of an incident cannot be identified. Stage Four: Mapping The raw event data ingested by an integration gets mapped to existing fields in Cortex XSOAR. The fields display incident data to analysts in the Cortex XSOAR graphical user interface (GUI). Ingestion >> Incident Creation >> Classification >> Mapping is the 100% correct answer

randomnametester

This is wrong