Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks XSOAR-Engineer Exam - Topic 5 Question 7 Discussion

When using the playbook debugger, what may be the cause of a starred incident missing from the Test Data selections?.
A) Closed incidents are not visible in the debugger.
B) The incident has been restricted.
C) Starred incidents are not visible in the debugger.
D) The incident type is set incorrectly.

Palo Alto Networks XSOAR-Engineer Exam - Topic 5 Question 7 Discussion

Actual exam question for Palo Alto Networks's XSOAR-Engineer exam
Question #: 7
Topic #: 5
[All XSOAR-Engineer Questions]

When using the playbook debugger, what may be the cause of a starred incident missing from the Test Data selections?.

Show Suggested Answer Hide Answer
Suggested Answer: A

The XSOAR Playbook Debugger allows engineers to simulate playbook behavior using existing incidents as sample data. The documentation explicitly states that only open incidents appear within the debugger's Test Data selection list. Closed incidents are removed from the selectable list because the debugger cannot execute against non-active incident states.

Starring an incident does not affect debugger availability; the star is a user-level convenience for bookmarking. RBAC restrictions (B) could hide an incident in general UI contexts but not selectively from the debugger. Incorrect incident type (D) also does not prevent selection as long as the incident is open.

Therefore, if a starred incident does not appear as a debugging option, the most common and documented reason is that the incident has been closed, and closed incidents cannot be used as debugger input. This aligns with option A.


Contribute your Thoughts:

0/2000 characters
Theodora
2 days ago
A sounds right. Closed incidents shouldn't show up.
upvoted 0 times
...
Vallie
7 days ago
I think it's B. The incident might be restricted.
upvoted 0 times
...
Princess
12 days ago
D sounds plausible too, wrong type could definitely cause issues.
upvoted 0 times
...
Shayne
17 days ago
C can't be true, starred incidents should be visible.
upvoted 0 times
...
Vince
2 months ago
Wait, are you saying starred incidents can be hidden? That's surprising!
upvoted 0 times
...
Alverta
2 months ago
I think B is the right answer. Restrictions can hide incidents.
upvoted 0 times
...
Jeniffer
2 months ago
A closed incident won't show up in the debugger.
upvoted 0 times
...
Candra
3 months ago
D could be a factor too, wrong type can mess things up.
upvoted 0 times
...
Hortencia
3 months ago
Definitely not C, starred incidents should show up.
upvoted 0 times
...
Edwin
3 months ago
Wait, are starred incidents really not visible? That seems odd.
upvoted 0 times
...
Shawana
3 months ago
I think B is the right answer. Restrictions can hide incidents.
upvoted 0 times
...
Yun
3 months ago
A closed incident won't show up in the debugger.
upvoted 0 times
...
Doug
3 months ago
I recall that incident types can definitely affect visibility, so D might be worth considering too.
upvoted 0 times
...
Aretha
4 months ago
I'm not entirely sure, but I feel like starred incidents should still be visible. Maybe C is misleading?
upvoted 0 times
...
Alexia
4 months ago
I think I saw a question like this in practice, and it mentioned restrictions on incidents. Could B be the answer?
upvoted 0 times
...
Quentin
4 months ago
I remember something about closed incidents not showing up in the debugger, so maybe A is correct?
upvoted 0 times
...

Save Cancel