Palo Alto Networks Certified Security Automation Engineer (PCSAE)Incident ManagementMedium

A security analyst is investigating a suspected data exfiltration incident. During the investigation, they discover a previously unknown IP address that is communicating with several internal hosts. This IP address is not currently tracked as an indicator of compromise (IOC) in any existing threat intelligence feeds. The analyst needs to quickly add this IP address to the incident as a new, ad-hoc observable for enrichment and future tracking. How can they achieve this most efficiently in Cortex XSOAR?

  1. ARun a playbook task that automatically extracts all IPs from the War Room.
  2. BCreate a new custom incident field for 'Newly Discovered IP'.
  3. CModify the incident layout to include a new 'IP Address' widget.
  4. DAdd the IP address to the incident's 'Indicators' tab manually.
Show answer & explanation

Correct answer: D. Add the IP address to the incident's 'Indicators' tab manually.

The 'Indicators' tab (or 'Observables' tab in newer versions) in Cortex XSOAR is specifically designed for adding and managing individual indicators of compromise (IOCs) or observables directly to an incident. Manually adding the IP here allows for immediate enrichment and tracking.

Why the other options are wrong

  • A. Running a playbook task to extract IPs from the War Room is for processing existing text, not for directly adding a known, specific new IP identified by the analyst.
  • B. Creating a new custom incident field is for structured data points, not for ad-hoc indicators that should be tracked as observables.
  • C. Modifying the incident layout is a configuration change, not an action for adding an ad-hoc observable to a live incident.

Cortex XSOAR Ad-hoc Observables

Cortex XSOAR allows analysts to manually add ad-hoc observables (e.g., IP addresses, file hashes, URLs) directly to an incident. These observables can then be automatically enriched, searched across other incidents, and used for further investigation.

  • Added via the 'Indicators' or 'Observables' tab.
  • Enables immediate enrichment by integrations.
  • Crucial for tracking newly discovered IOCs.
  • Supports various observable types (IP, URL, file, email).

Memory trick: Indicators Tab: Instantly Input the Important Info.

More Incident Management questions