Palo Alto Networks Certified Security Automation Engineer (PCSAE)Cortex XSOAR FundamentalsHard

A security analyst is managing user access in Cortex XSOAR. A new user, Jane Doe, needs to be able to view all incidents but only execute playbooks specifically tagged for 'Level 1 Triage'. She should not be able to modify any system settings. Which combination of XSOAR user management features should be used to grant Jane Doe these specific permissions?

  1. AGrant Jane 'Administrator' access for viewing and then manually revoke modify permissions.
  2. BAssign Jane to a default 'Analyst' role and rely on playbook permissions to restrict execution.
  3. CCreate a new role with 'Incident Viewer' and 'Execute Playbook' permissions, then use a Data Scope to restrict playbook execution.
  4. DAssign Jane to a role with 'Incident Viewer' permissions and a separate role with 'Triage Playbook Executor' permissions, then apply a Data Scope to the Triage role.
Show answer & explanation

Correct answer: D. Assign Jane to a role with 'Incident Viewer' permissions and a separate role with 'Triage Playbook Executor' permissions, then apply a Data Scope to the Triage role.

To achieve this granular control, Jane needs two distinct roles: one that grants broad incident viewing access, and another that grants playbook execution. Data scopes are then applied to the playbook execution role to limit which playbooks can be executed based on their tags, ensuring she only runs 'Level 1 Triage' playbooks.

Why the other options are wrong

  • A. 'Administrator' access grants full control, which contradicts the requirement to 'not modify any system settings'.
  • B. Relying solely on a default 'Analyst' role might grant too many permissions or not enough, and playbook-level permissions are typically managed via roles and scopes.
  • C. A Data Scope limits data *visibility*, not actions like 'execute playbook'. It cannot restrict playbook execution itself based on tags.

XSOAR Granular Access Control

The ability to define precise permissions for users based on their roles, group memberships, and data scopes within Cortex XSOAR.

  • Combines roles for actions (view, execute, modify).
  • Data Scopes filter visible data (incidents, indicators).
  • Permissions are additive; least restrictive typically applies.

Memory trick: Granular permissions are like having specific 'keys' for 'doors' and 'magnifying glasses' for 'data'.

More Cortex XSOAR Fundamentals questions