Palo Alto Networks Certified Security Automation Engineer (PCSAE)Automation and OrchestrationMedium

A financial institution is leveraging Cortex XSOAR for compliance automation. They need to generate weekly reports detailing access changes to critical systems, ensuring that every change is approved and logged according to regulatory requirements. Which type of XSOAR integration or feature would be most suitable for automatically collecting and verifying these access change logs from various systems?

  1. AVulnerability Management Integrations
  2. BSIEM/Log Management Integrations
  3. CEndpoint Detection and Response (EDR) Integrations
  4. DGeneric Webhook Trigger
Show answer & explanation

Correct answer: B. SIEM/Log Management Integrations

SIEM/Log Management Integrations are designed to connect Cortex XSOAR with platforms that consolidate logs from various systems. This allows for automated collection, parsing, and analysis of access change events necessary for compliance reporting.

Why the other options are wrong

  • A. Vulnerability Management Integrations focus on identifying software weaknesses, not system access changes.
  • C. EDR Integrations focus on endpoint security events, not necessarily comprehensive access change logs across all critical systems.
  • D. Generic Webhook Triggers are for receiving real-time alerts, not for systematically collecting historical logs for compliance.

Compliance Automation with Log Management

Automating the collection, analysis, and reporting of log data from various systems to demonstrate adherence to regulatory requirements, often leveraging SIEM/Log Management integrations.

  • Ensures audit trails for compliance.
  • Automates evidence collection.
  • Reduces manual effort in reporting.

Memory trick: Logs are the Key to Compliance Reports.

More Automation and Orchestration questions