Palo Alto Networks Certified Security Automation Engineer (PCSAE)Cortex XSOAR FundamentalsMedium
A new security analyst joins a SOC that uses Cortex XSOAR. The analyst needs to be able to view all incidents, run playbooks, and create new dashboards, but should not be able to modify system settings or manage user accounts. Which combination of XSOAR roles would provide the MINIMUM necessary permissions while adhering to the principle of least privilege?
- AAutomation Engineer + Integrations Administrator
- BAnalyst + Dashboard Administrator
- CAdministrator
- DViewer + Incidents Administrator
Show answer & explanationAnswer & explanation
Correct answer: B. Analyst + Dashboard Administrator
The 'Analyst' role provides permissions to view incidents and run playbooks. The 'Dashboard Administrator' role allows creating and managing dashboards. This combination grants the required access without providing administrative control over system settings or user management.
Why the other options are wrong
- A. Automation Engineer is for content development, and Integrations Administrator is for managing integrations, neither aligning with the primary requirements.
- C. Administrator grants full control, violating the principle of least privilege.
- D. Viewer is too restrictive (cannot run playbooks or create dashboards); Incidents Administrator is more than needed for just viewing.
Cortex XSOAR Role-Based Access Control (RBAC)
A security method that restricts system access to authorized users based on their role within the organization, using predefined or custom roles.
- Ensures least privilege
- Combines permissions for specific tasks
- Can be extended with data scopes
Memory trick: Roles define what you can 'Roll' with in XSOAR.