Palo Alto Networks Certified Security Automation Engineer (PCSAE)Automation and OrchestrationHard
A security architect is tasked with designing an automated vulnerability management workflow in Cortex XSOAR. The workflow needs to: 1) Ingest vulnerability scan results, 2) De-duplicate and prioritize vulnerabilities based on CVSS score and asset criticality, 3) Automatically create tickets in Jira for critical vulnerabilities, 4) Assign tickets to the appropriate team based on asset ownership (e.g., 'Web Team' for web servers, 'DB Team' for databases), and 5) Monitor Jira ticket status and close the corresponding vulnerability in XSOAR once patched. Which XSOAR feature is primarily responsible for performing step 4, the dynamic assignment of Jira tickets?
- ARole-Based Access Control (RBAC)
- BAutomated Reporting Dashboards
- CPlaybook with conditional logic and integrations
- DIncident Layout Customization
Show answer & explanationAnswer & explanation
Correct answer: C. Playbook with conditional logic and integrations
A playbook using conditional logic (e.g., 'if asset type is web server, then assign to Web Team') combined with an integration to a CMDB or asset management system to determine asset ownership, and an integration to Jira to update the ticket, is essential for dynamically assigning Jira tickets based on asset ownership.
Why the other options are wrong
- A. RBAC controls user permissions within XSOAR, not dynamic ticket assignment in an external system.
- B. Automated Reporting Dashboards visualize data, they do not perform dynamic assignment actions.
- D. Incident Layout Customization changes the UI, not the automation logic or assignment.
Dynamic Ticket Assignment
The automated process of assigning incident or vulnerability tickets to specific teams or individuals based on predefined rules, attributes (e.g., asset ownership, criticality), and integrations with external systems like CMDBs or ITSMs.
- Reduces manual triage and assignment overhead.
- Ensures tickets reach the correct remediation team faster.
- Requires conditional logic and integrations with asset management and ITSM systems.
Memory trick: Vulnerability playbooks find, prioritize, and assign to fix.