Palo Alto Networks Certified Security Automation Engineer (PCSAE)Cortex XSOAR FundamentalsHard

A large enterprise is planning to deploy Cortex XSOAR and needs to manage user access based on their department (e.g., HR, Finance, IT). Users in the HR department should only see incidents related to HR systems, while Finance users should only see finance-related incidents. They also want to ensure that if a user belongs to multiple departments, they can see incidents from all their assigned departments. Which XSOAR access control mechanism is best suited for this granular, multi-departmental incident visibility requirement?

  1. AData Scopes
  2. BMulti-Tenancy
  3. CActive/Passive Clustering
  4. DUser Roles
Show answer & explanation

Correct answer: A. Data Scopes

Data Scopes in Cortex XSOAR allow for granular control over which incidents (or other data types) specific users or groups can view, based on criteria like incident fields (e.g., department, tag). A user can be assigned multiple data scopes, allowing them to see data from all assigned categories.

Why the other options are wrong

  • B. Multi-Tenancy provides complete isolation between different organizations, not granular visibility within one organization across departments.
  • C. Active/Passive Clustering provides high availability, unrelated to data visibility.
  • D. User Roles define what actions a user can perform, not which specific data records they can see.

Cortex XSOAR Data Scopes

An access control mechanism in XSOAR that limits a user's view of data (e.g., incidents, indicators) based on specific criteria or attributes within those data records.

  • Granular data visibility control
  • Based on incident/indicator fields
  • Can combine multiple scopes for a user

Memory trick: Data Scopes 'Scope' out what you can see.

More Cortex XSOAR Fundamentals questions