Palo Alto Networks Certified Security Automation Engineer (PCSAE)Incident ManagementEasy

A security team uses Cortex XSOAR to manage incidents. They frequently encounter situations where an alert from their SIEM triggers a new incident, but a few minutes later, a very similar alert from the same source, related to the same entity (e.g., IP address, user), also triggers another incident. They want to automatically group these closely related incidents to avoid redundant investigations. Which XSOAR feature is specifically designed for this purpose?

  1. AIncident Correlation
  2. BIncident Types
  3. CIncident Dashboards
  4. DIncident Layouts
Show answer & explanation

Correct answer: A. Incident Correlation

Incident Correlation in Cortex XSOAR is specifically designed to automatically identify and group related incidents based on defined rules (e.g., same source, same entity, within a time window) to prevent redundant efforts and consolidate investigations.

Why the other options are wrong

  • B. Incident Types categorize incidents, but do not group related instances of those incidents.
  • C. Incident Dashboards provide aggregated views and reports, but do not perform dynamic grouping of new incoming incidents.
  • D. Incident Layouts customize the display of a single incident, not the grouping of multiple incidents.

Cortex XSOAR Incident Correlation

Incident Correlation in Cortex XSOAR automatically identifies and links related incidents based on predefined rules, such as common indicators (IPs, users), incident types, or timeframes. This helps consolidate investigations and reduce alert fatigue.

  • Automatically links incidents based on rules.
  • Reduces duplicate investigation efforts.
  • Can merge incidents or link them as related.
  • Configured via correlation rules in XSOAR.

Memory trick: Correlation Connects, Types Categorize, Layouts Look, Dashboards Display.

More Incident Management questions