Palo Alto Networks Certified Security Automation Engineer (PCSAE)Cortex XSOAR FundamentalsEasy
A security operations team is evaluating Cortex XSOAR for its potential to streamline their incident response process. They are particularly interested in its ability to automatically ingest alerts from various security tools, enrich incident data, and execute predefined response actions without manual intervention. Which primary function of Cortex XSOAR does this scenario highlight?
- ANetwork Detection and Response (NDR)
- BSecurity Orchestration, Automation, and Response (SOAR)
- CSecurity Information and Event Management (SIEM)
- DThreat Intelligence Management
Show answer & explanationAnswer & explanation
Correct answer: B. Security Orchestration, Automation, and Response (SOAR)
The scenario describes the core capabilities of Security Orchestration, Automation, and Response (SOAR) platforms: alert ingestion, data enrichment, and automated response actions, which is precisely what Cortex XSOAR provides.
Why the other options are wrong
- A. NDR focuses on network traffic analysis for detection, not overall incident response automation.
- C. SIEM focuses on log collection, correlation, and alerting, not automated response.
- D. Threat Intelligence Management is a component of SOAR but not its primary overarching function in this context.
Cortex XSOAR Core Function
Cortex XSOAR is a Security Orchestration, Automation, and Response (SOAR) platform designed to automate and orchestrate security operations.
- Automates incident response workflows
- Integrates with various security tools
- Enriches security alerts
Memory trick: XSOAR makes your SOC 'SOAR' with automation.