Palo Alto Networks Certified Security Automation Engineer (PCSAE)Incident ManagementEasy

A security analyst is investigating a critical phishing incident in Cortex XSOAR. They need to quickly access information about the sender's email address, the email subject, and the malicious URL extracted from the email body. Where would these specific data points typically be found within the incident's interface?

  1. AWar Room entries
  2. BIncident Fields
  3. CAudit Trail
  4. DPlaybook tasks
Show answer & explanation

Correct answer: B. Incident Fields

Incident Fields are dedicated data points within Cortex XSOAR designed to store specific pieces of information related to an incident, such as sender email, subject, or malicious URLs. They enable structured data collection and easy access.

Why the other options are wrong

  • A. War Room entries are for collaborative notes and command execution, not structured data storage.
  • C. The Audit Trail logs actions taken on an incident, not the incident's specific data content.
  • D. Playbook tasks represent automated or manual steps in a workflow, not data storage locations.

Cortex XSOAR Incident Fields

Incident Fields in Cortex XSOAR are structured data attributes that store specific pieces of information about an incident, such as attacker IP, affected users, or threat indicators. They facilitate consistent data collection and reporting.

  • Can be standard (built-in) or custom.
  • Displayed on incident layouts.
  • Used for filtering, searching, and reporting.
  • Populated manually or automatically by integrations/playbooks.

Memory trick: Fields fill in the facts; War Room chats, Playbooks act.

More Incident Management questions