Palo Alto Networks Certified Security Automation Engineer (PCSAE)Cortex XSOAR FundamentalsMedium
A security analyst is setting up a new XSOAR instance and needs to ensure that all user accounts are synchronized with their existing corporate LDAP directory for authentication and group membership. Which configuration is required to achieve this?
- AConfigure an LDAP integration instance.
- BConfigure SAML 2.0 for single sign-on.
- CSet up an active-active HA cluster.
- DInstall a dedicated XSOAR Engine.
Show answer & explanationAnswer & explanation
Correct answer: A. Configure an LDAP integration instance.
To synchronize user accounts and group memberships with an external directory like LDAP, Cortex XSOAR requires an LDAP integration instance to be configured. This integration allows XSOAR to query the LDAP directory for user authentication and to map LDAP groups to XSOAR roles.
Why the other options are wrong
- B. SAML 2.0 provides single sign-on but primarily for authentication, not for synchronizing group memberships from LDAP.
- C. An HA cluster provides high availability for the XSOAR server but is unrelated to user directory synchronization.
- D. An XSOAR Engine extends capabilities to remote networks but does not inherently provide directory synchronization functionality; an integration is still needed.
XSOAR LDAP Integration
Cortex XSOAR uses an LDAP integration to connect to external LDAP directories (e.g., Active Directory) for user authentication and synchronization of user and group information.
- Enables centralized user management.
- Allows mapping LDAP groups to XSOAR roles.
- Simplifies user provisioning and de-provisioning.
Memory trick: To connect your users to the corporate directory, you need an LDAP connector.