Palo Alto Networks Certified Security Automation Engineer (PCSAE)Incident ManagementEasy

A security analyst is investigating a phishing incident in Cortex XSOAR. They need to quickly identify all related incidents that share the same sender IP address and email subject line to understand the scope of the attack. Which feature in Cortex XSOAR would be most effective for this task?

  1. AWar Room collaboration
  2. BDashboard widgets
  3. CPlaybook task automation
  4. DIncident correlation rules
Show answer & explanation

Correct answer: D. Incident correlation rules

Incident correlation rules are specifically designed to group incidents based on common attributes, such as sender IP or subject, making it easy to identify related events for comprehensive investigation.

Why the other options are wrong

  • A. War Room is for real-time team collaboration on a single incident, not for identifying related incidents across the platform.
  • B. Dashboard widgets provide visual summaries of incident data but don't actively perform correlation or grouping of incidents.
  • C. Playbook task automation executes predefined steps within an incident, but doesn't inherently correlate incidents based on shared fields.

Incident Correlation

Incident correlation is the process of linking or grouping multiple security events or alerts into a single, more comprehensive incident based on shared attributes, patterns, or context.

  • Reduces alert fatigue by consolidating related alerts.
  • Provides a broader view of an attack's scope and impact.
  • Often uses rules or machine learning to identify relationships.

Memory trick: Correlate to consolidate, don't just collaborate.

More Incident Management questions