Palo Alto Networks Certified Security Automation Engineer (PCSAE)Incident ManagementHard

A global organization uses Cortex XSOAR to manage incidents across multiple regions. They have a strict compliance requirement to ensure that certain sensitive incident fields (e.g., specific PII, proprietary project names) are only visible to analysts with specific roles or located in particular geographical regions. How can this granular access control be implemented for incident fields in XSOAR?

  1. ABy configuring field-level permissions based on roles or user groups.
  2. BBy encrypting the entire incident database and providing decryption keys to authorized users.
  3. CBy using a global-level incident layout that hides sensitive fields for all users.
  4. DBy creating separate XSOAR tenants for each region and manually syncing non-sensitive data.
Show answer & explanation

Correct answer: A. By configuring field-level permissions based on roles or user groups.

Cortex XSOAR supports granular field-level permissions, allowing administrators to define which roles or user groups can view, edit, or hide specific incident fields, directly addressing the requirement for sensitive data visibility control.

Why the other options are wrong

  • B. Encrypting the entire database is a data at rest security measure, not a granular UI visibility control mechanism for specific fields within the application.
  • C. A global layout hides fields for *all* users or specific types, but doesn't offer the granular role-based or regional control required for *some* users to see them.
  • D. Creating separate tenants is an extreme measure for data segregation, not a primary or efficient way to manage field-level visibility within a single XSOAR instance for specific roles/regions.

XSOAR Field-Level Permissions

Field-level permissions in Cortex XSOAR allow administrators to control the visibility and editability of individual incident fields based on user roles, ensuring sensitive data is only accessible to authorized personnel.

  • Implemented via Role-Based Access Control (RBAC).
  • Can specify 'read-only', 'editable', or 'hidden' states.
  • Crucial for compliance and data privacy requirements.

Memory trick: Roles reveal fields, no peeking allowed.

More Incident Management questions