Free PCSAE Practice Test Questions and Answers (2026) | Cert Empire Practice Questions
Free preview: 20 questions.
Already purchased? Log in
Go
Question 1
Options
A:
Summary
B:
Compiler
C:
Schedule
D:
Run On
Show Answer
Discussion 0
Clear
Most voted
Newest
No comments yet. Be the first to comment.
Question 2
Options
A:
${Files.[2].Name}
B:
${Files.Name.[2]}
C:
${File.[1].Name}
D:
${File.Name.[1]}
Show Answer
Discussion 0
Clear
Most voted
Newest
No comments yet. Be the first to comment.
Question 3
Options
A:
Use File.Extension that does not equal (string comparison) PDF
B:
Use File.Name contains PDF
C:
Use File.Extension contains (general) PDF
D:
Use File.Extension equals (string comparison) PDF
Show Answer
Discussion 0
Clear
Most voted
Newest
No comments yet. Be the first to comment.
Question 4
Options
A:
Dashboards
B:
Threat Intel
C:
Settings
D:
Marketplace
Show Answer
Discussion 0
Clear
Most voted
Newest
No comments yet. Be the first to comment.
Question 5
Options
A:
Lists
B:
Jobs
C:
Pre-processing rules
D:
Exclusion List
Show Answer
Discussion 0
Clear
Most voted
Newest
No comments yet. Be the first to comment.
Question 6
Options
A:
2 main DBs, 1 application server, 2 node servers
B:
1 main DB, 1 application server, 3 node servers
C:
2 application servers, 1 main DB, 1 node server
D:
1 application server, 2 main DBs, 1 node server
Show Answer
Discussion 0
Clear
Most voted
Newest
No comments yet. Be the first to comment.
Question 7
Options
A:
Context, file, error, image
B:
Note, indicator, error, image
C:
Video, file, error, image
D:
Note, file, error, image
Show Answer
Discussion 0
Clear
Most voted
Newest
No comments yet. Be the first to comment.
Question 8
Options
A:
Classification and Mapping
B:
Playbook Tasks
C:
Evidence Fields
D:
Incident Fields
Show Answer
Discussion 0
Clear
Most voted
Newest
No comments yet. Be the first to comment.
Question 9
Options
A:
Using the demisto_error() function
B:
Using a print statement
C:
Using the demisto.debug() function
D:
Using the return_error() function
Show Answer
Discussion 0
Clear
Most voted
Newest
No comments yet. Be the first to comment.
Question 10
Options
A:
Set a field trigger script
B:
Associate to an incident type
C:
Change field type
D:
Change field name
Show Answer
Discussion 0
Clear
Most voted
Newest
No comments yet. Be the first to comment.
Question 11
Options
A:
All the data, including the incident key will be deleted, and the context data will be completely
empty.
B:
No difference, the automation cannot be executed manually.
C:
All context data, including custom incident fields will be deleted, system incident fields will
remain.
D:
All context data, except the incident key will be deleted.
Show Answer
Discussion 0
Clear
Most voted
Newest
No comments yet. Be the first to comment.
Question 12
Options
A:
Settings > Object Setup > Incidents > Layouts
B:
Settings > Integrations > Instance configuration
C:
Settings > Object Setup > Indicators > Layouts
D:
Settings > Advanced > Incident Layouts
Show Answer
Discussion 0
Clear
Most voted
Newest
No comments yet. Be the first to comment.
Question 13
Options
A:
XSOAR D2 agent
B:
external integration command
C:
XSOAR shared agent
D:
common automation script
Show Answer
Discussion 0
Clear
Most voted
Newest
No comments yet. Be the first to comment.
Question 14
Options
A:
Indicator type
B:
Incoming mapper
C:
Incident types
D:
Integration configuration
Show Answer
Discussion 0
Clear
Most voted
Newest
No comments yet. Be the first to comment.
Question 15
Options
A:
Create a custom playbook that sends an email each time the fetch fails.
B:
Create a new integration that monitors the incident fetch and sends an email if the fetch fails.
C:
Schedule a job that runs and monitors incidents in XSOAR that will send an email if there are no
new incidents.
D:
Add a server config to notify when incident fetch fails.
Show Answer
Discussion 0
Clear
Most voted
Newest
No comments yet. Be the first to comment.
Question 16
Options
A:
Data that is not mapped is placed under labels
B:
Only text fields are classified
C:
Classification cannot be used if mapping is enabled
D:
Every incoming field must be mapped
Show Answer
Discussion 0
Clear
Most voted
Newest
No comments yet. Be the first to comment.
Question 17
Options
A:
type:File reputation:Malicious sourcetimestamp:"30 days ago"
B:
type:File verdict:Malicious sourcetimestamp:<="30 days ago"
C:
type:File reputation:Malicious sourcetimestamp:="30 days ago"
D:
type:File verdict:Malicious sourcetimestamp:>="30 days ago"
Show Answer
Discussion 0
Clear
Most voted
Newest
No comments yet. Be the first to comment.
Question 18
Options
A:
By default, every 24 hours, the system closes any debugger sessions that have been open for more
than 180 minutes.
B:
The session must be stopped during 180 minutes manually by administrator, user will receive
notification automatically.
C:
The session will be running till stopped manually by administrator.
D:
By default, the system closes automatically any debugger session that have been open 180
minutes.
Show Answer
Discussion 0
Clear
Most voted
Newest
No comments yet. Be the first to comment.
Question 19
Options
A:
Remote repository based content sharing
B:
UI based content import/export button
C:
Copy the content backup from one environment file system (/var/lib/demisto/backup/content-
backup-*) and move it to the other environment
D:
Download the content items separately and upload them to the other environment
Show Answer
Discussion 0
Clear
Most voted
Newest
No comments yet. Be the first to comment.
Question 20
Options
A:
Define ‘parameters’
B:
Correlate to incident types
C:
Define ‘outputs’
D:
Set password protection
Show Answer
Discussion 0
Clear
Most voted
Newest
No comments yet. Be the first to comment.