Palo Alto Networks Certified Security Automation Engineer (PCSAE)Cortex XSOAR FundamentalsHard

A large enterprise is planning to deploy Cortex XSOAR and needs to manage user access based on their departmental roles (e.g., Tier 1 Analyst, Incident Responder, SOC Manager) and ensure they only see incidents relevant to their tasks. Which two features, when combined, best address these requirements?

  1. ARoles and Permissions; Multi-tenancy
  2. BEngines; Playbook Permissions
  3. CUser Groups; Incident Types
  4. DRoles and Permissions; Data Scopes
Show answer & explanation

Correct answer: D. Roles and Permissions; Data Scopes

Roles and Permissions define what actions users can perform (e.g., read, edit, delete), while Data Scopes determine which specific incidents or data entries users can view or interact with, allowing for granular control over data visibility based on their assignments.

Why the other options are wrong

  • A. Multi-tenancy provides strict logical separation for distinct business units, not granular data visibility within a single operational environment.
  • B. Engines extend execution capabilities, and Playbook Permissions control who can run playbooks, neither addresses granular incident data visibility.
  • C. User Groups simplify role assignment but don't inherently control data visibility. Incident Types categorize incidents but don't restrict access.

XSOAR Roles, Permissions, and Data Scopes

Cortex XSOAR uses Roles to define a set of Permissions (actions users can take) and Data Scopes (which data users can see) to control user access and data visibility.

  • Roles bundle specific permissions.
  • Permissions dictate what actions a user can perform (e.g., 'edit incident').
  • Data Scopes filter which data (e.g., 'incidents from specific teams') a user can view or interact with.

Memory trick: Your role is your job title, your permissions are what you can do, and your data scope is what you can see.

More Cortex XSOAR Fundamentals questions