Palo Alto Networks Certified Security Automation Engineer (PCSAE)Incident ManagementMedium
An organization uses Cortex XSOAR and has configured several incident types, each with its own customized layout. A new security analyst reports that when they create a 'Phishing' incident, they are presented with a generic layout that includes many irrelevant fields, rather than the specific 'Phishing Layout' designed for it. What is the most likely reason for this discrepancy?
- AThe 'Phishing Layout' is configured with an incorrect incident field order.
- BThe 'Phishing' incident type has not been correctly associated with the 'Phishing Layout'.
- CThe analyst's role permissions prevent them from seeing custom layouts.
- DThe system is defaulting to the 'Malware' incident type, which uses a generic layout.
Show answer & explanationAnswer & explanation
Correct answer: B. The 'Phishing' incident type has not been correctly associated with the 'Phishing Layout'.
For an incident type to display a specific custom layout, that layout must be explicitly associated with the incident type in its configuration. If this association is missing or incorrect, XSOAR will fall back to a default or generic layout.
Why the other options are wrong
- A. Incorrect field order would still display the correct fields, just in the wrong sequence, not a generic layout.
- C. Layout visibility is generally tied to the incident type, not directly restricted by role for custom layouts themselves, unless content pack permissions are involved which is less likely than a direct association issue.
- D. While possible, the analyst explicitly stated they are creating a 'Phishing' incident, making an incorrect incident type default less likely than a layout association issue.
Incident Layout Association
In Cortex XSOAR, an incident layout must be explicitly associated with one or more incident types. This ensures that when an incident of a particular type is created or viewed, the corresponding tailored layout is displayed, optimizing the analyst's workflow.
- Layouts customize the incident display.
- Association happens within the incident type configuration.
- Without association, a default layout is used.
- Improves analyst efficiency by presenting relevant fields.
Memory trick: Layouts Link to Types; No link, generic strife.