Palo Alto Networks Certified Security Automation Engineer (PCSAE)Incident ManagementHard

A security team receives numerous alerts daily, but many are false positives or low-priority informational alerts that do not require full incident response. They want to implement a mechanism in Cortex XSOAR to automatically close these benign alerts or assign them a 'low priority' status without human intervention, effectively reducing analyst workload. Which component is crucial for defining the logic and actions for this automated triage?

  1. AIncident fields for severity
  2. BIncident layouts for quick closure
  3. CPre-processing rules or automation scripts
  4. DDashboard widgets for alert volume
Show answer & explanation

Correct answer: C. Pre-processing rules or automation scripts

Pre-processing rules or automation scripts (often part of playbooks or incident type configurations) are used to define the logic for automatically analyzing incoming alerts and performing actions like closing them or assigning priority based on specific criteria, thus enabling automated triage.

Why the other options are wrong

  • A. Incident fields store severity, but don't define the logic for *assigning* or *changing* it automatically.
  • B. Incident layouts control UI presentation, not automation of triage actions.
  • D. Dashboard widgets visualize data but don't perform automation or triage actions.

XSOAR Automated Triage

Automated triage in Cortex XSOAR uses pre-defined rules, automation scripts, or playbooks to analyze incoming alerts and incidents, automatically categorizing, prioritizing, or closing them based on specific criteria, reducing manual effort.

  • Reduces false positives and analyst fatigue.
  • Ensures consistent initial handling of alerts.
  • Leverages conditional logic and integration capabilities.

Memory trick: Rules run the triage, no human passage.

More Incident Management questions