Palo Alto Networks Certified Security Automation Engineer (PCSAE)Incident ManagementMedium
A security analyst is investigating an incident where a critical server was compromised. They need to quickly add information about a newly discovered malicious IP address and its associated domain to the incident, ensuring it's easily visible and actionable for other analysts. Which incident management feature in Cortex XSOAR is best suited for this ad-hoc addition of related artifacts?
- AIncident Notes
- BWork Plan Tasks
- CObservables
- DCustom Incident Fields
Show answer & explanationAnswer & explanation
Correct answer: C. Observables
Observables (Indicators of Compromise or IoCs) are designed for tracking and managing artifacts like IP addresses, domains, and file hashes within an incident. They provide structured data that can be acted upon by playbooks and integrations.
Why the other options are wrong
- A. Incident notes are free-form text, not structured or directly actionable data.
- B. Work plan tasks define actions to be taken, not the artifacts themselves.
- D. Custom incident fields are for structured data on the incident itself, not for ad-hoc, actionable artifacts.
Cortex XSOAR Observables
Observables in Cortex XSOAR represent indicators of compromise (IoCs) or other relevant artifacts associated with an incident, such as IP addresses, domains, or file hashes.
- Structured data for artifacts.
- Can be automatically enriched and acted upon.
- Centralized tracking of IoCs within an incident.
Memory trick: Observables are the observable clues of an incident.