Palo Alto Networks Certified Security Automation Engineer (PCSAE)Cortex XSOAR FundamentalsHard

A security analyst is assigned to a user group in Cortex XSOAR that grants 'read-only' access to all incidents. However, the analyst is also individually assigned a specific role that grants 'full edit' access to incidents tagged 'critical'. If the analyst tries to modify an incident that is tagged 'critical', which permission will take precedence according to XSOAR's default behavior?

  1. AThe earliest assigned permission will take precedence.
  2. BThe 'full edit' access from the individual role.
  3. CThe 'read-only' access from the user group.
  4. DXSOAR will deny access, as there is a conflict.
Show answer & explanation

Correct answer: B. The 'full edit' access from the individual role.

Cortex XSOAR's permission model is additive. If a user is granted a specific permission (like 'full edit') through any means (individual role, user group, etc.), and another assignment grants a lesser permission (like 'read-only') for the same resource, the more permissive access takes precedence.

Why the other options are wrong

  • A. The timing of assignment does not influence precedence; it's about the highest granted permission.
  • C. This contradicts the additive nature of XSOAR permissions; more permissive access generally wins.
  • D. XSOAR does not deny access on conflict; it grants the highest level of access.

Cortex XSOAR Permission Precedence

XSOAR's access control model is additive; if a user receives conflicting permissions for a resource, the most permissive access granted takes precedence.

  • Additive permission model
  • Most permissive access wins
  • Applies to roles, groups, and individual assignments

Memory trick: Highest permission 'Wins' the access game.

More Cortex XSOAR Fundamentals questions