Palo Alto Networks Certified Security Automation Engineer (PCSAE)Cortex XSOAR FundamentalsMedium
A security analyst needs to retrieve detailed information about a specific incident, including all associated evidence, tasks, and notes, but is unable to see certain confidential fields within the incident layout. Which aspect of user management or permissions is most likely restricting their view?
- AMissing 'Playbook Executor' permission
- BInsufficient Data Scope for the incident
- CLack of 'Incident Editor' permission
- DIncorrectly assigned 'Analyst' role
Show answer & explanationAnswer & explanation
Correct answer: B. Insufficient Data Scope for the incident
Data Scopes control the visibility of specific data within Cortex XSOAR. If an analyst cannot see certain fields, it's likely their assigned Data Scope does not include the scope to which those confidential fields are assigned, even if they have the general permissions to view incidents.
Why the other options are wrong
- A. 'Playbook Executor' permission is for running playbooks and does not affect incident field visibility.
- C. 'Incident Editor' permission allows editing, not necessarily viewing restricted fields.
- D. An 'Analyst' role might grant general incident viewing, but specific field restrictions are typically controlled by Data Scopes, not the role itself.
Cortex XSOAR Data Scopes
Data Scopes in Cortex XSOAR define the specific sets of data (e.g., incidents, indicators, fields) that a user or role has permission to access and view.
- Used for granular data visibility control.
- Can restrict access to specific incident fields, types, or indicators.
- Often used in multi-departmental or multi-customer environments to ensure data segregation.
Memory trick: Your Data Scope is like a filter on your sunglasses, showing only what's allowed.