Palo Alto Networks Certified Security Automation Engineer (PCSAE)Automation and OrchestrationEasy
A security operations center (SOC) analyst is investigating a phishing incident where an employee clicked on a malicious link. The analyst needs to quickly identify all other employees who received the same phishing email and determine if they also clicked the link, to contain the threat. Which Cortex XSOAR automation capability is most effective for this scenario?
- AAutomated Incident Enrichment
- BThreat Intelligence Management
- CVulnerability Management Playbooks
- DCompliance Automation Workflows
Show answer & explanationAnswer & explanation
Correct answer: A. Automated Incident Enrichment
Automated incident enrichment allows the SOC to gather additional context and related information, such as other recipients and click actions, for an ongoing incident quickly and efficiently.
Why the other options are wrong
- B. Threat Intelligence Management deals with processing and applying external threat data, not incident specific data collection.
- C. Vulnerability Management Playbooks focus on identifying and remediating system weaknesses, not incident response.
- D. Compliance Automation Workflows ensure adherence to regulatory standards, which is not the primary goal here.
Automated Incident Enrichment
The process of automatically gathering additional contextual information related to a security incident to aid in investigation and response.
- Reduces manual data collection efforts.
- Provides a more complete picture of an incident.
- Integrates with various data sources (e.g., email gateways, EDR, identity systems).
Memory trick: XSOAR enriches incidents to light up the path to resolution.