Palo Alto Networks Certified Security Automation Engineer (PCSAE)Automation and OrchestrationMedium
A SOC manager wants to implement a 'shift left' strategy by empowering Tier 1 analysts to resolve common, low-severity incidents without escalating to Tier 2. This requires automating the initial investigation and remediation steps, providing clear instructions and pre-approved actions. Which Cortex XSOAR capability, when properly configured, enables this specific objective?
- ACustom Dashboards for real-time executive reporting.
- BAdvanced Machine Learning for anomaly detection.
- CPre-defined Playbooks with conditional logic and automated tasks.
- DComprehensive Threat Intelligence Feeds for all incidents.
Show answer & explanationAnswer & explanation
Correct answer: C. Pre-defined Playbooks with conditional logic and automated tasks.
Pre-defined playbooks with conditional logic and automated tasks allow Tier 1 analysts to execute standardized, repeatable response procedures, including investigation and remediation, without needing higher-tier expertise, thus enabling the 'shift left' strategy.
Why the other options are wrong
- A. Custom Dashboards are for reporting and monitoring, not for automating or empowering analysts in incident resolution.
- B. Machine learning for anomaly detection is for identifying threats, not for automating the response workflow for Tier 1 analysts.
- D. While threat intelligence is useful, simply having feeds doesn't automate the response or empower Tier 1 analysts for resolution.
'Shift Left' in SOC
A strategy in security operations to empower lower-tier analysts (e.g., Tier 1) to handle more complex or a broader range of incidents through automation and well-defined processes, reducing escalations to higher tiers.
- Reduces resolution times and operational costs.
- Requires robust automation and clear playbooks.
- Improves analyst efficiency and job satisfaction.
Memory trick: Shift left with playbooks, let Tier 1 take the lead.