Palo Alto Networks Certified Security Automation Engineer (PCSAE)Incident ManagementMedium

A security analyst is reviewing an incident in Cortex XSOAR and notices that several custom fields, critical for their investigation workflow, are not displayed on the default incident view. They need these fields to be prominently visible for all future incidents of this type. What is the most appropriate action to take?

  1. ACustomize the incident layout for that specific incident type.
  2. BExport the incident data and analyze it externally.
  3. CModify the incident's associated playbook to include a task to populate the fields.
  4. DAdjust the incident's severity and priority settings.
Show answer & explanation

Correct answer: A. Customize the incident layout for that specific incident type.

Incident layouts control which fields are visible and how they are organized on the incident details page. Customizing the layout for a specific incident type ensures critical fields are always displayed.

Why the other options are wrong

  • B. Exporting data is a workaround for analysis, not a solution for displaying fields within the XSOAR UI.
  • C. Modifying a playbook populates fields, but doesn't control their visibility on the UI.
  • D. Adjusting severity/priority is about incident handling, not field visibility.

Cortex XSOAR Incident Layouts

Incident layouts in Cortex XSOAR define the visual structure and presentation of incident details, including which fields are displayed, their order, and arrangement on the incident page.

  • Customizable per incident type.
  • Enhances user experience and efficiency for analysts.
  • Allows for grouping related fields and adding custom sections.

Memory trick: Layout makes fields look just right.

More Incident Management questions