Palo Alto Networks Certified Security Automation Engineer (PCSAE)Cortex XSOAR FundamentalsMedium

A security engineer is configuring user access in Cortex XSOAR and needs to understand the default behavior when a user is assigned to multiple roles with conflicting permissions. For example, User A is in 'Analyst Role' (can view all incidents) and 'Restricted Role' (can only view incidents tagged 'HR'). How does XSOAR determine User A's effective permissions for incident viewing?

  1. AThe most restrictive permission takes precedence.
  2. BThe least restrictive permission takes precedence.
  3. CThe first role assigned to the user takes precedence.
  4. DPermissions are determined by the role with the highest alphabetical order.
Show answer & explanation

Correct answer: B. The least restrictive permission takes precedence.

Cortex XSOAR follows a 'least restrictive' or 'additive' permission model. If a user is granted a permission by any role, they will have that permission, even if another role denies it or restricts it. In this case, 'view all incidents' is less restrictive than 'only view incidents tagged HR'.

Why the other options are wrong

  • A. This is incorrect; XSOAR typically applies the least restrictive permission.
  • C. The order of role assignment does not determine precedence in XSOAR's permission model.
  • D. Alphabetical order of role names does not influence permission precedence.

XSOAR Permission Precedence

The rule set that determines a user's effective permissions when they are assigned multiple roles with potentially conflicting access rights.

  • Least restrictive (additive) model is generally applied.
  • If any role grants a permission, the user has that permission.
  • Explicit 'deny' rules are rare; focus is on what is granted.

Memory trick: Think 'Open Door Policy': if any key opens it, it's open.

More Cortex XSOAR Fundamentals questions