Palo Alto Networks Certified Security Automation Engineer (PCSAE)Cortex XSOAR FundamentalsMedium
A security administrator needs to configure granular access control for different teams within a single Cortex XSOAR tenant. For example, the 'Threat Intel' team should only be able to view and modify indicators, while the 'Incident Response' team should only view and modify incidents. Which XSOAR feature is primarily used to define these distinct sets of permissions?
- APlaybooks
- BContent Packs
- CUser Groups
- DRoles
Show answer & explanationAnswer & explanation
Correct answer: D. Roles
Roles in Cortex XSOAR are collections of specific permissions that define what actions a user can perform (e.g., view incidents, edit indicators). By assigning different roles to different teams, granular access control can be achieved within a single tenant.
Why the other options are wrong
- A. Playbooks automate workflows but do not define user access permissions.
- B. Content Packs bundle integrations, playbooks, and other content but are not used for defining user permissions.
- C. User Groups are used to organize users for easier role assignment but do not define permissions themselves.
XSOAR Roles and Permissions
Roles in Cortex XSOAR are collections of specific permissions that dictate what actions a user or group is authorized to perform within the platform.
- Roles are assigned to users or user groups.
- Permissions define granular actions (e.g., create, read, update, delete) on specific XSOAR objects.
- Essential for implementing the principle of least privilege.
Memory trick: Your Role is your job title, dictating what doors you can open.