Palo Alto Networks Certified Security Automation Engineer (PCSAE)Incident ManagementMedium
A security analyst has identified a new type of malware targeting their organization. They want to create a structured approach in Cortex XSOAR to handle future incidents related to this malware, ensuring consistent data collection and automated response steps. This approach should include specific fields for malware family, infection vector, and remediation status, and trigger a dedicated playbook. Which of the following should the analyst define FIRST to achieve this?
- AA custom incident field for 'Malware Family'.
- BA new dashboard widget to track malware incidents.
- CAn automation script to update remediation status.
- DA new incident type tailored for this malware.
Show answer & explanationAnswer & explanation
Correct answer: D. A new incident type tailored for this malware.
Defining a new incident type is the foundational step as it allows for the association of specific custom fields, dedicated playbooks, and automation rules, creating a structured and consistent approach for handling a new category of incidents.
Why the other options are wrong
- A. While a custom incident field is needed, it must be associated with an incident type to be consistently used and displayed.
- B. A dashboard widget is for reporting and visualization, not for defining incident structure or automation.
- C. An automation script is a component of a playbook, which is triggered by an incident type, not the initial definition itself.
XSOAR Incident Type Definition
Defining an incident type in Cortex XSOAR involves creating a new category for incidents, specifying its default fields, associated playbooks, and automation rules to standardize handling.
- Establishes a template for consistent incident processing.
- Links custom fields, layouts, and playbooks.
- Crucial for organizing and automating incident response workflows.
Memory trick: Type defines the whole incident's stride.