Palo Alto Networks Certified Security Automation Engineer (PCSAE)Cortex XSOAR FundamentalsMedium

A security manager is reviewing the licensing model for a new Cortex XSOAR deployment. They notice that the license specifies a certain number of 'incidents per year' and a certain number of 'integrations'. What is the primary purpose of limiting 'incidents per year' in the XSOAR licensing model?

  1. ATo manage the overall data storage consumption by the XSOAR instance.
  2. BTo control the number of concurrent users accessing the platform.
  3. CTo restrict the geographical deployment locations of XSOAR Engines.
  4. DTo reflect the volume of security events and automation workload processed.
Show answer & explanation

Correct answer: D. To reflect the volume of security events and automation workload processed.

The 'incidents per year' limit in Cortex XSOAR licensing is a key metric that directly correlates with the volume of security events, alerts, and subsequent automation workload the platform is expected to handle, thus reflecting the value derived from the SOAR capabilities.

Why the other options are wrong

  • A. While incidents consume storage, the primary purpose of this metric is not storage control but rather workload volume.
  • B. Concurrent users are typically managed by user licenses or system resources, not incident count.
  • C. Geographical deployment of engines is unrelated to the incident count metric in licensing.

Cortex XSOAR Licensing Metrics

Key metrics in Cortex XSOAR licensing often include the number of incidents processed annually, the number of integrations, and sometimes user counts or engine counts.

  • Incidents per year reflect workload volume
  • Integrations count connected tools
  • Managed users may also be a metric

Memory trick: Incidents are the 'Currency' of XSOAR licensing.

More Cortex XSOAR Fundamentals questions